Weaknesses of type CWE-119

3,273 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2026-39870HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. PEPSS 0.4%CVE-2025-14333HIGHMemory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146EPSS 0.4%CVE-2026-10066HIGHShibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflowEPSS 0.4%CVE-2026-10065HIGHShibby Tomato tomatodata.cgi get_ups_field stack-based overflowEPSS 0.4%CVE-2026-10067HIGHShibby Tomato multimon.cgi sub_90F0 stack-based overflowEPSS 0.4%CVE-2024-10498MEDIUMCWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacEPSS 0.4%CVE-2026-14383HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2025-2357MEDIUMDCMTK dcmjpls JPEG-LS Decoder memory corruptionEPSS 0.4%CVE-2026-14407HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2023-35955HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35958HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35970HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-35956HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2021-1308HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-1251HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2025-1866CRITICALUndefined Behavior Due to Out-of-Bounds Pointer Arithmetic in libwebsocketsEPSS 0.4%CVE-2023-42047HIGHPDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-3812MEDIUMQEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_EPSS 0.4%CVE-2025-1368MEDIUMMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflowEPSS 0.4%CVE-2026-4719HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.4%