Falhas do tipo CWE-119

3.263 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2018-0292A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adEPSS 1.6%CVE-2025-4150HIGHNetgear EX6200 sub_54340 buffer overflowEPSS 1.5%CVE-2025-31277HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOEPSS 1.5%KEVCVE-2021-40117HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service VulnerabilityEPSS 1.5%CVE-2021-3942CRITICALCertain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of EPSS 1.5%CVE-2021-31883HIGHA vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions EPSS 1.5%CVE-2021-31882MEDIUMA vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions EPSS 1.5%CVE-2026-7853CRITICALD-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflowEPSS 1.5%CVE-2025-9938HIGHD-Link DI-8400 yyxz.asp yyxz_dlink_asp stack-based overflowEPSS 1.5%CVE-2021-31493HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User inEPSS 1.5%CVE-2019-1926HIGHCisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution VulnerabilitiesEPSS 1.5%CVE-2024-23213HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOSEPSS 1.5%CVE-2025-7911HIGHD-Link DI-8100 jhttpd upnp_ctrl.asp sprintf stack-based overflowEPSS 1.5%CVE-2014-0779Schneider Electric StruxureWare SCADA Expert ClearSCADA Improper Restriction of Operations within the Bounds of a Memory BufferEPSS 1.5%CVE-2019-1640HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilitiesEPSS 1.5%CVE-2019-1637HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilitiesEPSS 1.5%CVE-2019-1638HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilitiesEPSS 1.5%CVE-2023-33975CRITICALRIOT-OS vulnerable to Out of Bounds Write in _rbuf_addEPSS 1.5%CVE-2019-1639HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilitiesEPSS 1.5%CVE-2023-28391CRITICALA memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafEPSS 1.5%