Weaknesses of type CWE-119

3,263 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2023-31247CRITICALA memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specialEPSS 1.7%CVE-2023-28379CRITICALA memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially craEPSS 1.7%CVE-2025-7544HIGHTenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflowEPSS 1.7%CVE-2024-23617CRITICALSymantec Data Loss Prevention Buffer OverflowEPSS 1.7%CVE-2023-3138—A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values EPSS 1.7%CVE-2021-1278HIGHCisco SD-WAN Denial of Service VulnerabilitiesEPSS 1.7%CVE-2019-12807—Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing EPSS 1.6%CVE-2020-3500MEDIUMCisco StarOS IPv6 Denial of Service VulnerabilityEPSS 1.6%CVE-2025-4871MEDIUMPCMan FTP Server REST Command buffer overflowEPSS 1.6%CVE-2020-11058LOWImproper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDPEPSS 1.6%CVE-2024-23614CRITICALSymantec Messaging Gateway Buffer OverflowEPSS 1.6%CVE-2017-12278—A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, rEPSS 1.6%CVE-2026-8452HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceEPSS 1.6%KEVCVE-2021-34783HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Software-Based SSL/TLS Denial of Service VulnerabilityEPSS 1.6%CVE-2019-6571—A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS EPSS 1.6%CVE-2025-8169HIGHD-Link DIR-513 HTTP POST Request formSetWanPPTPpath formSetWanPPTPcallback buffer overflowEPSS 1.6%CVE-2025-1539HIGHD-Link DAP-1320 storagein.pd-XXXXXX replace_special_char stack-based overflowEPSS 1.6%CVE-2017-6669—Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attEPSS 1.6%CVE-2025-4148HIGHNetgear EX6200 sub_503FC buffer overflowEPSS 1.6%CVE-2025-4149HIGHNetgear EX6200 sub_54014 buffer overflowEPSS 1.6%