Weaknesses of type CWE-119

3,278 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2023-1676HIGHDriverGenius IOCTL mydrivers64.sys 0x9C402088 memory corruptionEPSS 0.4%CVE-2022-25662MEDIUMInformation disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdEPSS 0.4%CVE-2026-76757MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2024-12354MEDIUMSourceCodester Phone Contact Manager System User Menu MenuDisplayStart buffer overflowEPSS 0.4%CVE-2026-76756MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2026-76755MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2022-42809HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted gcx file maEPSS 0.4%CVE-2022-3541MEDIUMLinux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after freeEPSS 0.4%CVE-2022-3715HIGHA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory proEPSS 0.4%CVE-2022-0500—A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF EPSS 0.4%CVE-2025-2309MEDIUMHDF5 Type Conversion Logic H5T__bit_copy heap-based overflowEPSS 0.4%CVE-2025-29485MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to causeEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2026-52188MEDIUMBuffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the goheaEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2022-3636MEDIUMLinux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after freeEPSS 0.4%CVE-2020-8230—A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed toEPSS 0.4%CVE-2025-4892MEDIUMcode-projects Police Station Management System Delete Record source.cpp remove stack-based overflowEPSS 0.4%