Weaknesses of type CWE-119

3,287 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2020-27000—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%CVE-2025-5667MEDIUMFreeFloat FTP Server REIN Command buffer overflowEPSS 0.7%CVE-2026-8746MEDIUMOpen5GS NRF nghttp2-server.c discover_handler use after freeEPSS 0.7%CVE-2021-22761—A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.EPSS 0.7%CVE-2025-1352LOWGNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruptionEPSS 0.7%CVE-2025-9781HIGHTOTOLINK A702R formFilter sub_4162DC buffer overflowEPSS 0.7%CVE-2025-9779HIGHTOTOLINK A702R formFilter sub_4162DC buffer overflowEPSS 0.7%CVE-2025-9782HIGHTOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflowEPSS 0.7%CVE-2025-9780HIGHTOTOLINK A702R formIpQoS sub_419BE0 buffer overflowEPSS 0.7%CVE-2025-9783HIGHTOTOLINK A702R formParentControl sub_418030 buffer overflowEPSS 0.7%CVE-2025-5664MEDIUMFreeFloat FTP Server RESTART Command buffer overflowEPSS 0.7%CVE-2025-5595MEDIUMFreeFloat FTP Server PROGRESS Command buffer overflowEPSS 0.7%CVE-2025-5666MEDIUMFreeFloat FTP Server XMKD Command buffer overflowEPSS 0.7%CVE-2025-2752MEDIUMOpen Asset Import Library Assimp CSM File fast_atof.h fast_atoreal_move out-of-boundsEPSS 0.7%CVE-2025-5665MEDIUMFreeFloat FTP Server XCWD Command buffer overflowEPSS 0.7%CVE-2025-9812HIGHTenda CH22 exeCommand formexeCommand buffer overflowEPSS 0.7%CVE-2026-2139HIGHTenda TX9 fast_setting_wifi_set sub_432580 buffer overflowEPSS 0.7%CVE-2022-41193—Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusEPSS 0.7%CVE-2021-22543HIGHImproper memory handling in Linux KVMEPSS 0.7%CVE-2026-13587MEDIUMseladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflowEPSS 0.7%