Weaknesses of type CWE-119

3,289 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-4423HIGHSetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruptionEPSS 0.2%CVE-2025-11947LOWbftpd Configuration File options.c expand_groups heap-based overflowEPSS 0.2%CVE-2025-8851MEDIUMLibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflowEPSS 0.2%CVE-2026-28977MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS SeEPSS 0.2%CVE-2026-90577MEDIUMGPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflowEPSS 0.2%CVE-2025-14407LOWSoda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-43447MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watEPSS 0.2%CVE-2026-3382MEDIUMChaiScript boxed_number.hpp get_as memory corruptionEPSS 0.2%CVE-2026-2241MEDIUMjanet-lang janet os.c os_strftime out-of-boundsEPSS 0.2%CVE-2021-46757HIGHInsufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel EPSS 0.2%CVE-2023-31352MEDIUMA bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private dEPSS 0.2%CVE-2026-1260HIGHInvalid Memory Access in Sentencepiece,EPSS 0.2%CVE-2025-9732MEDIUMDCMTK dcm2img diybrpxt.h memory corruptionEPSS 0.2%CVE-2026-20795HIGHImproper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial ofEPSS 0.2%CVE-2026-22887HIGHImproper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of serviceEPSS 0.2%CVE-2026-3437CRITICALImproper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering ToolkitsEPSS 0.2%CVE-2025-2029MEDIUMMicroDicom DICOM Viewer mDicom.exe memory corruptionEPSS 0.2%CVE-2026-2889MEDIUMCCExtractor mp4.c processmp4 use after freeEPSS 0.2%CVE-2026-5037MEDIUMmxml mxmlIndexNew mxml-index.c index_sort stack-based overflowEPSS 0.2%CVE-2026-55586MEDIUMSumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM filesEPSS 0.2%