Weaknesses of type CWE-119

3,282 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-15189HIGHD-Link DWR-M920 formDefRoute sub_464794 buffer overflowEPSS 0.8%CVE-2024-22080CRITICALAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur duringEPSS 0.8%CVE-2025-24216MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS SeEPSS 0.8%CVE-2023-3261HIGHThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 liEPSS 0.8%CVE-2026-5318MEDIUMLibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds writeEPSS 0.8%CVE-2025-8760CRITICALINSTAR 2K+/4K fcgi_server base64_decode buffer overflowEPSS 0.8%CVE-2022-43607HIGHAn out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbEPSS 0.8%CVE-2025-15431HIGHUTT 进取 512W formFtpServerDirConfig strcpy buffer overflowEPSS 0.8%CVE-2025-15430HIGHUTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflowEPSS 0.8%CVE-2025-14993HIGHTenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflowEPSS 0.8%CVE-2025-10948HIGHMikroTik RouterOS libjson.so print parse_json_element buffer overflowEPSS 0.8%CVE-2026-2138HIGHTenda TX9 SetStaticRouteCfg sub_42D03C buffer overflowEPSS 0.8%CVE-2026-2140HIGHTenda TX9 setMacFilterCfg sub_4223E0 buffer overflowEPSS 0.8%CVE-2026-2137HIGHTenda TX3 SetIpMacBind buffer overflowEPSS 0.8%CVE-2023-34341HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locatioEPSS 0.8%CVE-2021-46023HIGHAn Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation faEPSS 0.8%CVE-2025-43343CRITICALThe issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visiEPSS 0.8%CVE-2026-2705MEDIUMOpen Babel MOL2 File atom.h SetFormalCharge out-of-boundsEPSS 0.8%CVE-2025-15090HIGHUTT 进取 512W formConfigNoticeConfig strcpy buffer overflowEPSS 0.8%CVE-2025-15089HIGHUTT 进取 512W APSecurity strcpy buffer overflowEPSS 0.8%