Falhas do tipo CWE-119

3.265 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-6752HIGHLinksys WRT1900ACS/EA7200/EA7450/EA7500 IGD Layer3Forwarding SetDefaultConnectionService stack-based overflowEPSS 1.1%CVE-2018-17905When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may ocEPSS 1.1%CVE-2025-8242HIGHTOTOLINK X15 HTTP POST Request formFilter buffer overflowEPSS 1.1%CVE-2021-3496A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.EPSS 1.1%CVE-2025-9297HIGHTenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflowEPSS 1.1%CVE-2025-31219HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, mEPSS 1.1%CVE-2025-5910HIGHTOTOLINK EX1200T HTTP POST Request formWsc buffer overflowEPSS 1.1%CVE-2025-5911HIGHTOTOLINK EX1200T HTTP POST Request formDMZ buffer overflowEPSS 1.1%CVE-2020-28220MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versioEPSS 1.1%CVE-2025-31257MEDIUMThis issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvEPSS 1.1%CVE-2022-22706HIGHArm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 througEPSS 1.1%KEVCVE-2025-8810HIGHTenda AC20 SetFirewallCfg strcpy stack-based overflowEPSS 1.1%CVE-2025-8170HIGHTOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflowEPSS 1.1%CVE-2026-7855HIGHD-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflowEPSS 1.1%CVE-2021-33737HIGHA vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 Advanced (incl. SIPLUS variEPSS 1.1%CVE-2025-7854HIGHTenda FH451 VirtualSer fromVirtualSer stack-based overflowEPSS 1.1%CVE-2025-7551HIGHTenda FH1201 PPTPDClient fromPptpUserAdd stack-based overflowEPSS 1.1%CVE-2025-7586HIGHTenda AC500 setWtpData formSetAPCfg stack-based overflowEPSS 1.1%CVE-2025-7531HIGHTenda FH1202 PPTPUserSetting fromPptpUserSetting stack-based overflowEPSS 1.1%CVE-2025-7463HIGHTenda FH1201 HTTP POST Request AdvSetWrlsafeset formWrlsafeset buffer overflowEPSS 1.1%