Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-13566MEDIUMjarun nnn nnn.c run_cmd_as_plugin double freeEPSS 0.1%CVE-2026-2069MEDIUMggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowEPSS 0.1%CVE-2023-52548HIGHHuawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leEPSS 0.1%CVE-2025-21096LOWImproper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilegeEPSS 0.1%CVE-2026-10230MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflowEPSS 0.1%CVE-2022-25681HIGHPossible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caEPSS 0.1%CVE-2022-25682HIGHMemory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon CEPSS 0.1%CVE-2022-25661HIGHMemory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdragonEPSS 0.1%CVE-2023-31351MEDIUMImproper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integEPSS 0.1%CVE-2026-10229MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.1%CVE-2025-9338HIGHA improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered byEPSS 0.1%CVE-2026-11623LOWtmux image.c image_free use after freeEPSS 0.1%CVE-2026-10200MEDIUMAssimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflowEPSS 0.1%CVE-2025-36156HIGHIBM InfoSphere Data Replication VSAM for z/OS Remote Source code executionEPSS 0.1%CVE-2022-33210HIGHMemory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large EPSS 0.1%CVE-2026-10528MEDIUMOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflowEPSS 0.1%CVE-2026-10231MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflowEPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2026-92059CRITICALIncorrect boundary conditions in the DOM: Editor componentEPSS 0.1%CVE-2024-23369HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%