Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-82596MEDIUMLatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corruptionEPSS 0.2%CVE-2026-64714MEDIUMA memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden GEPSS 0.2%CVE-2026-4010MEDIUMThakeeNathees pocketlang pkByteBufferAddString memory corruptionEPSS 0.2%CVE-2026-4009MEDIUMjarikomppa soloud WAV File dr_wav.h drwav_read_pcm_frames_s16__msadpcm out-of-boundsEPSS 0.2%CVE-2026-18790MEDIUMSysterel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-boundsEPSS 0.2%CVE-2025-15667MEDIUMGPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double freeEPSS 0.2%CVE-2026-3950MEDIUMstrukturag libheif stsz/stts track.cc load out-of-boundsEPSS 0.2%CVE-2026-3949MEDIUMstrukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-boundsEPSS 0.2%CVE-2026-90681MEDIUMMatthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-boundsEPSS 0.2%CVE-2025-12875MEDIUMmruby array.c ary_fill_exec out-of-bounds writeEPSS 0.2%CVE-2026-15185MEDIUMGPAC MP4Box vobsub.c vobsub_read_idx out-of-boundsEPSS 0.2%CVE-2026-4016MEDIUMGPAC SVG Parser load_svg.c svgin_process out-of-bounds writeEPSS 0.2%CVE-2026-18785MEDIUMo6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after freeEPSS 0.2%CVE-2026-3979MEDIUMquickjs-ng quickjs quickjs.c js_iterator_concat_return use after freeEPSS 0.2%CVE-2026-7135MEDIUMGPAC MP4Box box_code_base.c elng_box_read out-of-boundsEPSS 0.2%CVE-2026-92475MEDIUMGPAC downloader.c wait_for_header_and_parse out-of-boundsEPSS 0.2%CVE-2026-19108MEDIUMMZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after freeEPSS 0.2%CVE-2026-84567MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2026-7582MEDIUMAcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds writeEPSS 0.2%CVE-2025-11010MEDIUMvstakhov libucl ucl_util.c ucl_include_common heap-based overflowEPSS 0.2%