Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-23356HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%CVE-2026-58005HIGHUnvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3.EPSS 0.1%CVE-2024-21482MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in Linux Boot LoaderEPSS 0.1%CVE-2026-20731MEDIUMImproper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. UnEPSS 0.1%CVE-2026-34864MEDIUMBoundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2025-36510MEDIUMImproper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denialEPSS 0.1%CVE-2023-31317HIGHImproper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read orEPSS 0.1%CVE-2023-43554HIGHImproper Restriction of Operations withing the Bounds of a Memory Buffer in DSP ServicesEPSS 0.1%CVE-2024-43049HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2024-43053HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2024-51394MEDIUMBuffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a dEPSS 0.1%CVE-2025-62623HIGHA heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially EPSS 0.1%CVE-2023-21047MEDIUMIn ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local infEPSS 0.1%CVE-2023-20605MEDIUMIn keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SyEPSS 0.1%CVE-2022-38690MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2022-42775MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2025-20073LOWImproper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an information disclosure. SEPSS 0.1%CVE-2022-39131MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2025-20005MEDIUMImproper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System softwaEPSS 0.1%CVE-2023-21044MEDIUMIn init of VendorGraphicBufferMeta, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatiEPSS 0.1%