Weaknesses of type CWE-119

3,277 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-6516MEDIUMHDF5 H5Fint.c H5F_addr_decode_len heap-based overflowEPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%CVE-2023-42841HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPEPSS 0.4%CVE-2025-4069MEDIUMcode-projects Product Management System add_item stack-based overflowEPSS 0.4%CVE-2025-3763MEDIUMSourceCodester Phone Management System Password main buffer overflowEPSS 0.4%CVE-2026-12305HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2025-4059MEDIUMcode-projects Prison Management System Prison_Mgmt_Sys addrecord stack-based overflowEPSS 0.4%CVE-2025-3166MEDIUMcode-projects Product Management System Search Product Menu search_item stack-based overflowEPSS 0.4%CVE-2025-4068MEDIUMcode-projects Simple Movie Ticket Booking System changeprize stack-based overflowEPSS 0.4%CVE-2025-4077MEDIUMcode-projects School Billing System searchrec stack-based overflowEPSS 0.4%CVE-2022-41180—Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2025-4471MEDIUMcode-projects Jewelery Store Management system Search Item View stack-based overflowEPSS 0.4%CVE-2023-36746HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specEPSS 0.4%CVE-2022-39808—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%CVE-2026-12220HIGHYealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflowEPSS 0.4%CVE-2026-12218HIGHYealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflowEPSS 0.4%CVE-2026-43740MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.4%CVE-2026-12221HIGHYealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflowEPSS 0.4%CVE-2026-12222HIGHYealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflowEPSS 0.4%