Weaknesses of type CWE-119

3,268 results

Corrupção de memória genérica

Fraqueza ampla que descreve qualquer escrita ou leitura inadequada de dados na memória do programa, violando os limites esperados de um buffer, estrutura ou alocação. O risco é grave: pode levar a travamento, execução de código arbitrário ou exposição de dados sensíveis, dependendo de como o atacante explora o acesso descontrolado.

Example

Um programa C lê mais bytes de um array do que deveria (estouro de buffer clássico), ou escreve em endereço de memória inválido após liberar um ponteiro. Em ambos os casos, dados adjacentes são sobrescrevidos ou corrompidos, causando comportamento impredizível ou crash.

How to mitigate

Use verificações de limites antes de qualquer acesso indexado; prefira linguagens com gerenciamento automático de memória (Go, Rust, Python) quando possível; em C/C++, empregue ferramentas como AddressSanitizer em testes e ASLR+DEP/NX em produção para dificultar exploração. Revise ponteiros e aritmética de buffer em code review.

CVE-2019-15245HIGHCisco SPA100 Series Analog Telephone Adapters Remote Code Execution VulnerabilitiesEPSS 0.6%CVE-2019-15242HIGHCisco SPA100 Series Analog Telephone Adapters Remote Code Execution VulnerabilitiesEPSS 0.6%CVE-2019-15244HIGHCisco SPA100 Series Analog Telephone Adapters Remote Code Execution VulnerabilitiesEPSS 0.6%CVE-2019-15251HIGHCisco SPA100 Series Analog Telephone Adapters Remote Code Execution VulnerabilitiesEPSS 0.6%CVE-2025-1594MEDIUMFFmpeg AAC Encoder aacenc_tns.c ff_aac_search_for_tns stack-based overflowEPSS 0.6%CVE-2019-15240HIGHCisco SPA100 Series Analog Telephone Adapters Remote Code Execution VulnerabilitiesEPSS 0.6%CVE-2021-1527MEDIUMCisco Webex Player Memory Corruption VulnerabilityEPSS 0.6%CVE-2025-32033HIGHApollo Router Operation Limits Vulnerable to Bypass via Integer OverflowEPSS 0.6%CVE-2022-42278HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memorEPSS 0.6%CVE-2025-3203MEDIUMTenda W18E setModules formSetAccountList stack-based overflowEPSS 0.6%CVE-2026-2180HIGHTenda RX3 fast_setting_wifi_set stack-based overflowEPSS 0.6%CVE-2022-41184—Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted EPSS 0.6%CVE-2021-4010—A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSEPSS 0.6%CVE-2021-4009—A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreateEPSS 0.6%CVE-2025-9362MEDIUMLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 urlFilterManageRule stack-based overflowEPSS 0.6%CVE-2026-74989CRITICALInternally found bugs fixed in Thunderbird 154EPSS 0.6%CVE-2023-40052HIGHProgress Application Server (PAS) for OpenEdge Denial of ServiceEPSS 0.6%CVE-2026-9605MEDIUMGNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflowEPSS 0.6%CVE-2026-86716MEDIUMCesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflowEPSS 0.6%CVE-2017-12283—A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unautEPSS 0.6%