Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2023-28550HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in MPP PerformanceEPSS 0.1%CVE-2023-28551HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in UTILSEPSS 0.1%CVE-2026-92076HIGHIncorrect boundary conditions in the Networking componentEPSS 0.1%CVE-2023-21628HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HALEPSS 0.1%CVE-2022-25713HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in AutomotiveEPSS 0.1%CVE-2023-28549HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN HALEPSS 0.1%CVE-2023-21633MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21637MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21663MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in DisplayEPSS 0.1%CVE-2022-33267MEDIUMImproper restriction of operations within the bounds of memory buffer in LinuxEPSS 0.1%CVE-2026-10232MEDIUMAssimp ASE File scene.cpp ~aiNode use after freeEPSS 0.1%CVE-2023-21654MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in AudioEPSS 0.1%CVE-2024-21481HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HypervisorEPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2026-10233MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-boundsEPSS 0.1%CVE-2026-12216MEDIUMsvaarala duktape duk_api_bytecode.c memory corruptionEPSS 0.1%CVE-2021-25518MEDIUMAn improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2024-23356HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%CVE-2026-92065HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%CVE-2026-92064HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%