Weaknesses of type CWE-787

5,154 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-40654HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2022-40653HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2024-44284MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, mEPSS 0.6%CVE-2023-51742MEDIUMBuffer Overflow vulnerability in Skyworth RouterEPSS 0.6%CVE-2026-31402CRITICALnfsd: fix heap overflow in NFSv4.0 LOCK replay cacheEPSS 0.6%CVE-2022-40652HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.6%CVE-2023-32158HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-1017CRITICALMemory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7EPSS 0.6%CVE-2024-5695CRITICALIf an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been tEPSS 0.6%CVE-2024-6817HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-5701CRITICALMemory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2024-6815HIGHIrfanView RLE File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-39927HIGHOut-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected EPSS 0.6%CVE-2026-16907HIGHIBM i is Affected By Multiple Vulnerabilities in the Debug ServerEPSS 0.6%CVE-2024-30374HIGHLuxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-41184—Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted EPSS 0.6%CVE-2022-1841HIGHOut-of-bound write in tcp_flagsEPSS 0.6%CVE-2026-62648HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated EPSS 0.6%CVE-2025-0910HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%