Weaknesses of type CWE-119

3,271 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-9356HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 inboundFilterAdd stack-based overflowEPSS 1.0%CVE-2021-3746—A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by speciaEPSS 1.0%CVE-2025-9361HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 ipRangeBlockManageRule stack-based overflowEPSS 1.0%CVE-2025-10034HIGHD-Link DIR-825 httpd ping6_response.cg get_ping6_app_stat buffer overflowEPSS 1.0%CVE-2022-35032MEDIUMOTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.EPSS 1.0%CVE-2021-32492—A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may leaEPSS 1.0%CVE-2022-35024MEDIUMOTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.EPSS 1.0%CVE-2025-7603HIGHD-Link DI-8100 HTTP Request jingx.asp stack-based overflowEPSS 1.0%CVE-2025-7602HIGHD-Link DI-8100 HTTP Request arp_sys.asp stack-based overflowEPSS 1.0%CVE-2026-2877HIGHTenda A18 Httpd Service WifiExtraSet strcpy stack-based overflowEPSS 1.0%CVE-2025-9246HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 check_port_conflict stack-based overflowEPSS 1.0%CVE-2025-9251HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 sta_wps_pin stack-based overflowEPSS 1.0%CVE-2025-9248HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_pingGatewayByBBS stack-based overflowEPSS 1.0%CVE-2025-9249HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DHCPReserveAddGroup stack-based overflowEPSS 1.0%CVE-2025-9247HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setVlan stack-based overflowEPSS 1.0%CVE-2025-9253HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflowEPSS 1.0%CVE-2026-2876HIGHTenda A18 setBlackRule parse_macfilter_rule stack-based overflowEPSS 1.0%CVE-2025-9252HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DisablePasswordAlertRedirect stack-based overflowEPSS 1.0%CVE-2026-3044HIGHTenda AC8 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflowEPSS 1.0%CVE-2025-9250HIGHLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setPWDbyBBS stack-based overflowEPSS 1.0%