Weaknesses of type CWE-119

3,277 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2026-11516MEDIUMUTT HiPER 2610G formNatStaticMap strcpy buffer overflowEPSS 0.4%CVE-2026-84145HIGHInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2025-62594MEDIUMImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)EPSS 0.4%CVE-2019-10142HIGHA flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parametEPSS 0.4%CVE-2025-1364MEDIUMMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflowEPSS 0.4%CVE-2025-0412HIGHLuxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2025-9184HIGHMemory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.4%CVE-2025-4480MEDIUMcode-projects Simple College Management System Add New Student input stack-based overflowEPSS 0.4%CVE-2020-36881HIGHFlexsense DiskBoss 'Add Input Directory' Buffer OverflowEPSS 0.4%CVE-2025-4497MEDIUMcode-projects Simple Banking System Sign In buffer overflowEPSS 0.4%CVE-2025-11721CRITICALMemory safety bug fixed in Firefox 144 and Thunderbird 144EPSS 0.4%CVE-2026-28941HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. PEPSS 0.4%CVE-2026-90716MEDIUMmarcobambini Gravity Number gravity_parser.c parse_number_expression out-of-boundsEPSS 0.4%CVE-2026-7324HIGHMemory safety bugs fixed in Thunderbird 150.0.1EPSS 0.4%CVE-2024-0772MEDIUMNsasoft ShareAlarmPro Registration memory corruptionEPSS 0.4%CVE-2025-52566HIGHllama.cpp tokenizer signed vs. unsigned heap overflowEPSS 0.4%CVE-2025-1367MEDIUMMicroWord eScan Antivirus USB Password sprintf buffer overflowEPSS 0.4%CVE-2023-2873MEDIUMTwister Antivirus IoControlCode filppd.sys 0x80800043 memory corruptionEPSS 0.4%CVE-2026-12326HIGHMemory safety bugs fixed in Firefox 152 and Thunderbird 152EPSS 0.4%