Weaknesses of type CWE-119

3,289 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-13566MEDIUMjarun nnn nnn.c run_cmd_as_plugin double freeEPSS 0.1%CVE-2026-2069MEDIUMggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowEPSS 0.1%CVE-2023-52548HIGHHuawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leEPSS 0.1%CVE-2025-21096LOWImproper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilegeEPSS 0.1%CVE-2026-10230MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflowEPSS 0.1%CVE-2022-25681HIGHPossible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caEPSS 0.1%CVE-2022-25682HIGHMemory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon CEPSS 0.1%CVE-2022-25661HIGHMemory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdragonEPSS 0.1%CVE-2023-31351MEDIUMImproper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integEPSS 0.1%CVE-2026-10229MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.1%CVE-2026-10200MEDIUMAssimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflowEPSS 0.1%CVE-2025-9338HIGHA improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered byEPSS 0.1%CVE-2026-10528MEDIUMOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflowEPSS 0.1%CVE-2026-11623LOWtmux image.c image_free use after freeEPSS 0.1%CVE-2025-36156HIGHIBM InfoSphere Data Replication VSAM for z/OS Remote Source code executionEPSS 0.1%CVE-2022-33210HIGHMemory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large EPSS 0.1%CVE-2026-10231MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflowEPSS 0.1%CVE-2026-92059CRITICALIncorrect boundary conditions in the DOM: Editor componentEPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2024-23369HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%