Weaknesses of type CWE-119

3,283 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2023-48267HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2022-28200HIGHNVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond EPSS 0.2%CVE-2025-6275MEDIUMWebAssembly wabt binary-reader-interp.cc GetFuncOffset use after freeEPSS 0.2%CVE-2026-10703MEDIUMEIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after freeEPSS 0.2%CVE-2025-11277MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflowEPSS 0.2%CVE-2025-9385MEDIUMappneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after freeEPSS 0.2%CVE-2026-96676MEDIUMFast FAC1900R uhttpd get_alias_name stack-based overflowEPSS 0.2%CVE-2023-4949HIGHMemory Corruption Vulnerability in Grub-Legacy's XFS ImplementationEPSS 0.2%CVE-2026-1418MEDIUMGPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds writeEPSS 0.2%CVE-2023-46837LOWarm32: The cache may not be properly cleaned/invalidated (take two)EPSS 0.2%CVE-2024-47046HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2025-11014MEDIUMOGRECave Ogre Image OgreSTBICodec.cpp encode heap-based overflowEPSS 0.2%CVE-2021-36343HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2025-9386MEDIUMappneta tcpreplay tcprewrite get.c get_l2len_protocol use after freeEPSS 0.2%CVE-2025-3148MEDIUMcodeprojects Product Management System Login buffer overflowEPSS 0.2%CVE-2023-48368MEDIUMImproper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of servicEPSS 0.2%CVE-2025-7284HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7285HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-11495MEDIUMGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowEPSS 0.2%CVE-2026-3137MEDIUMCodeAstro Food Ordering System food_ordering.exe stack-based overflowEPSS 0.2%