Weaknesses of type CWE-119

3,285 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2014-125025MEDIUMFFmpeg decode_pulses memory corruptionEPSS 0.7%CVE-2014-125019MEDIUMFFmpeg Slice Segment decode_nal_unit memory corruptionEPSS 0.7%CVE-2014-125013MEDIUMFFmpeg msrle.c msrle_decode_frame memory corruptionEPSS 0.7%CVE-2014-125008MEDIUMFFmpeg oggparsevorbis.c vorbis_header memory corruptionEPSS 0.7%CVE-2022-3662HIGHAxiomatic Bento4 mp42hls Ap4Sample.h GetOffset use after freeEPSS 0.7%CVE-2022-3666HIGHAxiomatic Bento4 mp42ts Ap4LinearReader.cpp Advance use after freeEPSS 0.7%CVE-2025-5550MEDIUMFreeFloat FTP Server PBSZ Command buffer overflowEPSS 0.7%CVE-2025-5593MEDIUMFreeFloat FTP Server HOST Command buffer overflowEPSS 0.7%CVE-2022-34764MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service wEPSS 0.7%CVE-2025-5547MEDIUMFreeFloat FTP Server CDUP Command buffer overflowEPSS 0.7%CVE-2025-5636MEDIUMPCMan FTP Server SET Command buffer overflowEPSS 0.7%CVE-2025-5637MEDIUMPCMan FTP Server SYSTEM Command buffer overflowEPSS 0.7%CVE-2025-5592MEDIUMFreeFloat FTP Server PASSIVE Command buffer overflowEPSS 0.7%CVE-2025-5594MEDIUMFreeFloat FTP Server SET Command buffer overflowEPSS 0.7%CVE-2025-5551MEDIUMFreeFloat FTP Server SYSTEM Command buffer overflowEPSS 0.7%CVE-2025-5596MEDIUMFreeFloat FTP Server REGET Command buffer overflowEPSS 0.7%CVE-2025-5549MEDIUMFreeFloat FTP Server PASV Command buffer overflowEPSS 0.7%CVE-2025-1147LOWGNU Binutils nm nm.c internal_strlen buffer overflowEPSS 0.7%CVE-2021-21794CRITICALAn out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafEPSS 0.7%CVE-2020-27006—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%