Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-84537MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2025-23398HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2025-23400HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2026-6776HIGHIncorrect boundary conditions in the WebRTC: Networking componentEPSS 0.2%CVE-2023-28587HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in BT ControllerEPSS 0.2%CVE-2026-5186MEDIUMNothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double freeEPSS 0.2%CVE-2025-9020LOWPX4 PX4-Autopilot Mavlink Shell Closing mavlink_receiver.cpp handle_message_serial_control use after freeEPSS 0.2%CVE-2023-41779MEDIUMIllegal Memory Access Vulnerability of ZTE's ZXCLOUD iRAIEPSS 0.2%CVE-2026-22167HIGHGPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryEPSS 0.2%CVE-2025-1246HIGHMali GPU Userspace Driver allows an Out-of-Bounds accessEPSS 0.2%CVE-2024-33016MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in StorageEPSS 0.2%CVE-2024-36434HIGHAn SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.EPSS 0.2%CVE-2024-36433HIGHAn arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware beforEPSS 0.2%CVE-2025-20053HIGHImproper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enableEPSS 0.2%CVE-2024-0162MEDIUMDell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local lowEPSS 0.2%CVE-2026-36910MEDIUMAn access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial oEPSS 0.2%CVE-2026-43767MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.1%CVE-2025-33044MEDIUMexFat Memory Corruption IssueEPSS 0.1%CVE-2025-58409LOWGPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes corrupting memoryEPSS 0.1%CVE-2025-15013MEDIUMfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflowEPSS 0.1%