Weaknesses of type CWE-119

3,265 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-6752HIGHLinksys WRT1900ACS/EA7200/EA7450/EA7500 IGD Layer3Forwarding SetDefaultConnectionService stack-based overflowEPSS 1.1%CVE-2018-17905—When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may ocEPSS 1.1%CVE-2025-8242HIGHTOTOLINK X15 HTTP POST Request formFilter buffer overflowEPSS 1.1%CVE-2021-3496—A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.EPSS 1.1%CVE-2025-31219HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, mEPSS 1.1%CVE-2025-9297HIGHTenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflowEPSS 1.1%CVE-2025-5910HIGHTOTOLINK EX1200T HTTP POST Request formWsc buffer overflowEPSS 1.1%CVE-2025-5911HIGHTOTOLINK EX1200T HTTP POST Request formDMZ buffer overflowEPSS 1.1%CVE-2020-28220MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versioEPSS 1.1%CVE-2025-31257MEDIUMThis issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvEPSS 1.1%CVE-2022-22706HIGHArm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 througEPSS 1.1%KEVCVE-2025-8810HIGHTenda AC20 SetFirewallCfg strcpy stack-based overflowEPSS 1.1%CVE-2025-8170HIGHTOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflowEPSS 1.1%CVE-2026-7855HIGHD-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflowEPSS 1.1%CVE-2021-33737HIGHA vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 Advanced (incl. SIPLUS variEPSS 1.1%CVE-2025-7854HIGHTenda FH451 VirtualSer fromVirtualSer stack-based overflowEPSS 1.1%CVE-2025-7551HIGHTenda FH1201 PPTPDClient fromPptpUserAdd stack-based overflowEPSS 1.1%CVE-2025-7586HIGHTenda AC500 setWtpData formSetAPCfg stack-based overflowEPSS 1.1%CVE-2025-7531HIGHTenda FH1202 PPTPUserSetting fromPptpUserSetting stack-based overflowEPSS 1.1%CVE-2025-7463HIGHTenda FH1201 HTTP POST Request AdvSetWrlsafeset formWrlsafeset buffer overflowEPSS 1.1%