Weaknesses of type CWE-119

3,282 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2023-2977HIGHA vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attaEPSS 0.3%CVE-2026-24798CRITICALAn Uninitialized stack variable vulnerability in GaijinEntertainment/DagorEngineEPSS 0.3%CVE-2025-53965MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480,EPSS 0.3%CVE-2022-32926MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchEPSS 0.3%CVE-2022-24419HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-3595LOWLinux Kernel CIFS sess.c sess_free_buffer double freeEPSS 0.3%CVE-2022-24420HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24415HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24421HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24416HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2025-6693HIGHRT-Thread device.c sys_device_write memory corruptionEPSS 0.3%CVE-2024-9731HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-29574MEDIUMBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.EPSS 0.3%CVE-2026-12317HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-29571MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of EPSS 0.3%CVE-2025-3007MEDIUMNovastar CX40 NetFilter Utility netconfig getopt stack-based overflowEPSS 0.3%CVE-2025-52264HIGHStarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.EPSS 0.3%CVE-2020-27797—An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2025-8177MEDIUMLibTIFF thumbnail.c setrow buffer overflowEPSS 0.3%CVE-2020-27798—An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%