Weaknesses of type CWE-119

3,289 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2023-28550HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in MPP PerformanceEPSS 0.1%CVE-2023-28551HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in UTILSEPSS 0.1%CVE-2026-92076HIGHIncorrect boundary conditions in the Networking componentEPSS 0.1%CVE-2023-21628HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HALEPSS 0.1%CVE-2022-25713HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in AutomotiveEPSS 0.1%CVE-2023-28549HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN HALEPSS 0.1%CVE-2023-21633MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21637MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21663MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in DisplayEPSS 0.1%CVE-2022-33267MEDIUMImproper restriction of operations within the bounds of memory buffer in LinuxEPSS 0.1%CVE-2026-10232MEDIUMAssimp ASE File scene.cpp ~aiNode use after freeEPSS 0.1%CVE-2023-21654MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in AudioEPSS 0.1%CVE-2024-21481HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HypervisorEPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2026-10233MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-boundsEPSS 0.1%CVE-2026-12216MEDIUMsvaarala duktape duk_api_bytecode.c memory corruptionEPSS 0.1%CVE-2021-25518MEDIUMAn improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2024-23356HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%CVE-2026-92065HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%CVE-2026-92064HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%