Weaknesses of type CWE-119

3,271 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2026-10160HIGHTRENDnet TEW-432BRP formSetEnableWizard stack-based overflowEPSS 0.5%CVE-2026-10122HIGHTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowEPSS 0.5%CVE-2025-9185HIGHMemory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.5%CVE-2025-24222MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web contentEPSS 0.5%CVE-2026-10119HIGHTRENDnet TEW-432BRP formSetMACFilter stack-based overflowEPSS 0.5%CVE-2026-10123HIGHTRENDnet TEW-432BRP formSetDomainFilter stack-based overflowEPSS 0.5%CVE-2026-82618MEDIUMSysterel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-boundsEPSS 0.5%CVE-2026-7322HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2022-1778HIGHA vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ...EPSS 0.5%CVE-2026-19999MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-86514MEDIUMvgmstream txth-txtp txth.c sscanf stack-based overflowEPSS 0.5%CVE-2026-12805MEDIUMOFFIS DCMTK ofxml.cc parseFile heap-based overflowEPSS 0.5%CVE-2024-22170CRITICALUnchecked buffer in Dynamic DNS clientEPSS 0.5%CVE-2026-16360CRITICALMemory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153EPSS 0.5%CVE-2026-64757HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.5%CVE-2025-26265MEDIUMA segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification EPSS 0.5%CVE-2026-20268HIGHCisco IOS XE Software Security Hardening ReleaseEPSS 0.5%CVE-2026-20319HIGHCisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management VulnerabilitiesEPSS 0.5%CVE-2026-11522HIGHTenda W20E setPortMirror formSetPortMirror stack-based overflowEPSS 0.5%CVE-2026-11523HIGHTenda W20E Web Management PortalAuth formPortalAuth stack-based overflowEPSS 0.5%