Weaknesses of type CWE-119

3,283 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-4183MEDIUMPCMan FTP Server RECV Command buffer overflowEPSS 0.8%CVE-2025-4184MEDIUMPCMan FTP Server QUOTE Command buffer overflowEPSS 0.8%CVE-2025-3725MEDIUMPCMan FTP Server MIC Command buffer overflowEPSS 0.8%CVE-2021-40398HIGHAn out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted malformeEPSS 0.7%CVE-2025-0840MEDIUMGNU Binutils objdump.c disassemble_bytes stack-based overflowEPSS 0.7%CVE-2022-24938MEDIUMMalformed Zigbee packet causes Assert in EmberZNet 7.0.1 or earlierEPSS 0.7%CVE-2025-14994HIGHTenda FH1201/FH1206 HTTP Request webtypelibrary strcat stack-based overflowEPSS 0.7%CVE-2020-3544HIGHCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Remote Code Execution and Denial of Service VulnerabilityEPSS 0.7%CVE-2026-1143HIGHTOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg buffer overflowEPSS 0.7%CVE-2026-7069HIGHD-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflowEPSS 0.7%CVE-2024-20076HIGHIn Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional eEPSS 0.7%CVE-2025-43213MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOEPSS 0.7%CVE-2024-6236HIGHDenial of ServiceEPSS 0.7%CVE-2024-20077HIGHIn Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional eEPSS 0.7%CVE-2026-16013MEDIUMliftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-boundsEPSS 0.7%CVE-2025-47869CRITICALApache NuttX RTOS: examples/xmlrpc: Fix calls buffers size.EPSS 0.7%CVE-2025-14992HIGHTenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflowEPSS 0.7%CVE-2025-13258HIGHTenda AC20 WifiExtraSet buffer overflowEPSS 0.7%CVE-2025-15217HIGHTenda AC23 HTTP POST Request formSetPPTPUserList buffer overflowEPSS 0.7%CVE-2024-9401CRITICALMemory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence EPSS 0.7%