Weaknesses of type CWE-787

5,154 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-38986CRITICALThe HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulneEPSS 0.6%CVE-2026-34588HIGHOpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/WriteEPSS 0.6%CVE-2022-35939HIGHOut of bounds write in `scatter_nd` op in TensorFlow LiteEPSS 0.6%CVE-2026-44634HIGHStack buffer overflows in SimpleBLEEPSS 0.6%CVE-2021-3713—An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device useEPSS 0.6%CVE-2023-24056MEDIUMIn pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuEPSS 0.6%CVE-2026-28859MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS EPSS 0.6%CVE-2026-44747CRITICALMemory Corruption vulnerability in SAP NetWeaver Application Server ABAPEPSS 0.6%CVE-2025-53844HIGHA out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allowEPSS 0.6%CVE-2024-22667HIGHVim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is paEPSS 0.6%CVE-2020-14331—A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the EPSS 0.6%CVE-2020-13878CRITICALIrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.EPSS 0.6%CVE-2020-13880CRITICALIrfanView B3D PlugIns before version 4.56 has a B3d.dll!+1cbf heap-based out-of-bounds write.EPSS 0.6%CVE-2020-13879CRITICALIrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.EPSS 0.6%CVE-2022-41578CRITICALThe MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation EPSS 0.6%CVE-2018-16880MEDIUMA flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions,EPSS 0.6%CVE-2026-20616HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma EPSS 0.6%CVE-2022-39806—Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Drawing (.slddrw, CoreCadTranslator.exe) file receivedEPSS 0.6%CVE-2022-0843HIGHMozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugsEPSS 0.6%CVE-2024-20068MEDIUMIn modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional EPSS 0.6%