Weaknesses of type CWE-119

3,273 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2018-7522—In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixedEPSS 0.4%CVE-2024-11523HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11524HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-43794HIGHA memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10,EPSS 0.4%CVE-2025-7464MEDIUMosrg GoBGP rtr.go SplitRTR out-of-boundsEPSS 0.4%CVE-2026-90815MEDIUMFFmpeg Convolution Filter vf_convolution.c setup_3x3 out-of-boundsEPSS 0.4%CVE-2024-27344HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-21634MEDIUMA malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery prEPSS 0.4%CVE-2026-8093HIGHMemory safety bugs fixed in Firefox 150.0.2EPSS 0.4%CVE-2026-90572MEDIUMdavenardella snap7 s7_micro_client.cpp opUpload memory corruptionEPSS 0.4%CVE-2025-33076HIGHIBM Engineering Systems Design Rhapsody code executionEPSS 0.4%CVE-2023-35969HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-35957HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-39486HIGHPDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-4390MEDIUMTeamSpeak 3 Server Connection State Management process_resend_queue use after freeEPSS 0.4%CVE-2021-3674HIGHA flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted valEPSS 0.4%CVE-2025-52582HIGHAn out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafEPSS 0.4%CVE-2026-87444HIGHMemory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vEPSS 0.4%CVE-2022-3161HIGH The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execuEPSS 0.4%CVE-2020-27787—A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalidEPSS 0.4%