Weaknesses of type CWE-119

3,283 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2025-4239MEDIUMPCMan FTP Server TYPE Command buffer overflowEPSS 0.7%CVE-2025-5219MEDIUMFreeFloat FTP Server ASCII Command buffer overflowEPSS 0.7%CVE-2025-4251MEDIUMPCMan FTP Server RMDIR Command buffer overflowEPSS 0.7%CVE-2025-5073MEDIUMFreeFloat FTP Server MKDIR Command buffer overflowEPSS 0.7%CVE-2025-5356MEDIUMFreeFloat FTP Server BYE Command buffer overflowEPSS 0.7%CVE-2025-4844MEDIUMFreeFloat FTP Server CD Command buffer overflowEPSS 0.7%CVE-2025-3845MEDIUMmarkparticle WebServer buffer.cpp HasWritten buffer overflowEPSS 0.7%CVE-2020-13495MEDIUMAn exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed fEPSS 0.7%CVE-2022-24937MEDIUMMalformed Zigbee packet causes Assert in EmberZNet 7.0.0 or earlierEPSS 0.7%CVE-2025-13400HIGHTenda CH22 WrlExtraGet formWrlExtraGet buffer overflowEPSS 0.7%CVE-2026-2071HIGHUTT 进取 520W formP2PLimitConfig strcpy buffer overflowEPSS 0.7%CVE-2026-2070HIGHUTT 进取 520W formPolicyRouteConf strcpy buffer overflowEPSS 0.7%CVE-2026-93962MEDIUMKamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflowEPSS 0.7%CVE-2026-2066HIGHUTT 进取 520W formIpGroupConfig strcpy buffer overflowEPSS 0.7%CVE-2026-92399MEDIUMGPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflowEPSS 0.7%CVE-2026-4391MEDIUMTeamSpeak 3 Server ECC Key heap-based overflowEPSS 0.7%CVE-2026-91091MEDIUMGPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruptionEPSS 0.7%CVE-2026-75090MEDIUMEricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_tokenizer out-of-boundsEPSS 0.7%CVE-2025-12345HIGHLLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflowEPSS 0.7%CVE-2026-10270HIGHD-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflowEPSS 0.7%