Weaknesses of type CWE-119

3,273 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2024-38268MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versEPSS 0.4%CVE-2024-38269MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmwarEPSS 0.4%CVE-2026-8954HIGHIncorrect boundary conditions, integer overflow in the Audio/Video componentEPSS 0.4%CVE-2026-19933MEDIUMDefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflowEPSS 0.4%CVE-2024-38266MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware vEPSS 0.4%CVE-2026-4185MEDIUMGPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflowEPSS 0.4%CVE-2026-14241HIGHMemory safety bugs fixed in Firefox 152.0.4EPSS 0.4%CVE-2022-33162HIGHIBM Directory Server buffer overflowEPSS 0.4%CVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.4%CVE-2022-3545MEDIUMLinux Kernel IPsec nfp_cppcore.c area_cache_get use after freeEPSS 0.4%CVE-2026-4734CRITICALHeap Buffer Overflow in yoyofr/modizerEPSS 0.4%CVE-2025-2148LOWPyTorch Tuple torch.ops.profiler._call_end_callbacks_on_jit_fut memory corruptionEPSS 0.4%CVE-2021-3598—There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted fEPSS 0.4%CVE-2026-4738CRITICALGDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code ExecutionEPSS 0.4%CVE-2026-9637HIGHCompactLogix® 5380 / ControlLogix® 5580 - Multiple VulnerabilitiesEPSS 0.4%CVE-2022-3635MEDIUMLinux Kernel IPsec idt77252.c tst_timer use after freeEPSS 0.4%CVE-2024-11523HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11524HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11519HIGHIrfanView RLE File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11528HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%