Weaknesses of type CWE-119

3,289 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2022-34415HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34413HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34410HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34417HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34409HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-9500MEDIUMGNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflowEPSS 0.2%CVE-2022-34421HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-18784MEDIUMo6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflowEPSS 0.2%CVE-2022-34416HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34414HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34407HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-19259MEDIUMMZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflowEPSS 0.2%CVE-2026-8258MEDIUMSquirrel sqstdstring.cpp validate_format stack-based overflowEPSS 0.2%CVE-2026-5235MEDIUMAxiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflowEPSS 0.2%CVE-2025-15666MEDIUMOpen Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflowEPSS 0.2%CVE-2026-5236MEDIUMAxiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflowEPSS 0.2%CVE-2026-33851HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in joncampbell123 doslibEPSS 0.2%CVE-2026-19886HIGHOriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-5185MEDIUMNothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflowEPSS 0.2%CVE-2026-91090LOWGPAC base_scenegraph.c gf_node_activate_ex stack-based overflowEPSS 0.2%