Weaknesses of type CWE-119

3,283 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2020-7261MEDIUMBuffer overwrite in ENS allowed to bypass AMSI protectionEPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2024-11261MEDIUMSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruptionEPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2023-51257HIGHAn invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.EPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%CVE-2024-13941MEDIUMouch-org ouch zip.rs convert_zip_date_time memory corruptionEPSS 0.3%CVE-2026-92071CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.3%CVE-2024-23133HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2025-6269MEDIUMHDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflowEPSS 0.3%CVE-2026-8087MEDIUMOSGeo gdal GDapi.c GDnentries heap-based overflowEPSS 0.3%CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2025-6270MEDIUMHDF5 H5FSsection.c H5FS__sect_find_node heap-based overflowEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2025-14861HIGHMemory safety bugs fixed in Firefox 146.0.1EPSS 0.3%CVE-2022-41173—Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sEPSS 0.3%CVE-2022-41171—Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusEPSS 0.3%CVE-2022-41182—Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTranslator.exe) file receEPSS 0.3%CVE-2026-64788MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27,EPSS 0.3%CVE-2022-41169—Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrEPSS 0.3%