Weaknesses of type CWE-119

3,272 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2026-0892CRITICALMemory safety bugs fixed in Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2025-43373HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AEPSS 0.5%CVE-2026-6752HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-6753HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-8973HIGHMemory safety bugs fixed in Firefox 151EPSS 0.5%CVE-2025-2755MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-boundsEPSS 0.5%CVE-2026-8389HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2026-7323HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2022-38692CRITICALIn BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without rEPSS 0.5%CVE-2023-3471HIGHBuffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.5%CVE-2026-43795MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2026-65338MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2026-65334MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10EPSS 0.5%CVE-2022-0367—A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.EPSS 0.5%CVE-2026-65335MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2025-0753MEDIUMAxiomatic Bento4 mp42aac ReadPartial heap-based overflowEPSS 0.5%CVE-2026-65330MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2026-100740CRITICALD-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds writeEPSS 0.5%CVE-2026-19967MEDIUMOpen Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflowEPSS 0.5%CVE-2026-19970MEDIUMOpen Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 heap-based overflowEPSS 0.5%