Weaknesses of type CWE-119

3,283 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-4792MEDIUMFreeFloat FTP Server MDELETE Command buffer overflowEPSS 0.7%CVE-2025-5295MEDIUMFreeFloat FTP Server PORT Command buffer overflowEPSS 0.7%CVE-2025-5635MEDIUMPCMan FTP Server PLS Command buffer overflowEPSS 0.7%CVE-2025-5050MEDIUMFreeFloat FTP Server BELL Command buffer overflowEPSS 0.7%CVE-2026-2521MEDIUMOpen5GS SGW-C sgwc_s5c_handle_create_session_response memory corruptionEPSS 0.7%CVE-2017-3196—PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outsEPSS 0.7%CVE-2025-5220MEDIUMFreeFloat FTP Server GET Command buffer overflowEPSS 0.7%CVE-2025-5075MEDIUMFreeFloat FTP Server DEBUG Command buffer overflowEPSS 0.7%CVE-2026-2192HIGHTenda AC9 formGetRebootTimer stack-based overflowEPSS 0.7%CVE-2026-2191HIGHTenda AC9 formGetDdosDefenceList stack-based overflowEPSS 0.7%CVE-2025-13553HIGHD-Link DWR-M920 formPinManageSetup sub_41C7FC buffer overflowEPSS 0.7%CVE-2025-15215HIGHTenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflowEPSS 0.7%CVE-2024-13903MEDIUMquickjs-ng QuickJS qjs quickjs.c JS_GetRuntime stack-based overflowEPSS 0.7%CVE-2026-82623MEDIUMopen62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after freeEPSS 0.7%CVE-2025-43435MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOSEPSS 0.7%CVE-2023-32331HIGHIBM Connect:Express for UNIX denial of serviceEPSS 0.7%CVE-2025-5218MEDIUMFreeFloat FTP Server LITERAL Command buffer overflowEPSS 0.7%CVE-2025-4290MEDIUMPCMan FTP Server SMNT Command buffer overflowEPSS 0.7%CVE-2025-4238MEDIUMPCMan FTP Server MGET Command buffer overflowEPSS 0.7%CVE-2025-5221MEDIUMFreeFloat FTP Server QUOTE Command buffer overflowEPSS 0.7%