Weaknesses of type CWE-119

3,278 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2020-27799—A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2026-20698MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOEPSS 0.3%CVE-2025-1187MEDIUMcode-projects Police FIR Record Management System Delete Record stack-based overflowEPSS 0.3%CVE-2026-12200MEDIUMRitlabs TinyWeb Server Header libeay32.dll.html stack-based overflowEPSS 0.3%CVE-2025-6093MEDIUMuYanki board-stm32f103rc-berial heartrate1_hal.c heartrate1_i2c_hal_write stack-based overflowEPSS 0.3%CVE-2025-8040HIGHMemory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.3%CVE-2023-1679MEDIUMDriverGenius IOCTL mydrivers64.sys 0x9C40A108 memory corruptionEPSS 0.3%CVE-2025-53618HIGHAn out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DIEPSS 0.3%CVE-2026-92035CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2026-92045CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2022-28194HIGHNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker wEPSS 0.3%CVE-2026-7346HIGHInappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory acceEPSS 0.3%CVE-2022-41192—Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusteEPSS 0.3%CVE-2024-21961MEDIUMImproper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtualEPSS 0.3%CVE-2022-41188—Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untruEPSS 0.3%CVE-2023-30431HIGHIBM Db2 buffer overflowEPSS 0.3%CVE-2025-4038MEDIUMcode-projects Train Ticket Reservation System reservation stack-based overflowEPSS 0.3%CVE-2024-24921HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application is vulnerable to memory corruptEPSS 0.3%CVE-2026-12192HIGHGALAYOU Y4 Web Server buffer overflowEPSS 0.3%CVE-2025-3196MEDIUMOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflowEPSS 0.3%