Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-15013MEDIUMfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflowEPSS 0.1%CVE-2025-9157MEDIUMappneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after freeEPSS 0.1%CVE-2025-33195MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A succeEPSS 0.1%CVE-2025-13120MEDIUMmruby array.c sort_cmp use after freeEPSS 0.1%CVE-2024-11495HIGHBuffer overflow in OllyDbgEPSS 0.1%CVE-2025-11015MEDIUMOGRECave Ogre OgreSTBICodec.cpp encode mismatched memory management routinesEPSS 0.1%CVE-2025-10824MEDIUMaxboe fio init.c __parse_jobs_ini use after freeEPSS 0.1%CVE-2026-12193HIGHVS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflowEPSS 0.1%CVE-2022-34376LOW Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may EPSS 0.1%CVE-2025-22885MEDIUMImproper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a priviEPSS 0.1%CVE-2023-21634MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in Radio Interface LayerEPSS 0.1%CVE-2023-28545HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in TZ Secure OSEPSS 0.1%CVE-2025-55286HIGHz2d OOB drawing with new multi-sample anti-aliasing could lead to invalid memory access and corruptionEPSS 0.1%CVE-2026-1465HIGHA heap-based buffer over-read or buffer overflow in tildearrow/furnaceEPSS 0.1%CVE-2026-20621MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS EPSS 0.1%CVE-2023-28586MEDIUMImproper Restriction of Operation within the Bounds of a Memory Buffer in TZ Secure OSEPSS 0.1%CVE-2025-14569MEDIUMggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeEPSS 0.1%CVE-2026-30883MEDIUMImageMagick has a Heap Overflow when writing extremely large image profile in the PNG encoderEPSS 0.1%CVE-2026-2245MEDIUMCCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-boundsEPSS 0.1%CVE-2025-13566MEDIUMjarun nnn nnn.c run_cmd_as_plugin double freeEPSS 0.1%