Weaknesses of type CWE-787

5,155 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-55827HIGHFreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decodeEPSS 0.5%CVE-2026-6786HIGHMemory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2023-27344HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27345HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-35788HIGHAn issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write inEPSS 0.5%CVE-2023-27343HIGHPDF-XChange Editor EMF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-20182HIGHCisco Adaptive Security Appliance Software, Firepower Threat Defense Software and IOS XE Software IKEv2 Denial of Service VulnerabilityEPSS 0.5%CVE-2025-43237CRITICALAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cEPSS 0.5%CVE-2024-37036CRITICALCWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and paEPSS 0.5%CVE-2026-5190HIGHAWS C Event Stream Streaming Decoder Stack Buffer OverflowEPSS 0.5%CVE-2018-10883MEDIUMA flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a deEPSS 0.5%CVE-2025-66945CRITICALA path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /EPSS 0.5%CVE-2026-2681MEDIUMGithub.com/supranational/blst: blst cryptographic library: denial of service via out-of-bounds stack write in key generationEPSS 0.5%CVE-2026-87121CRITICALOut-of-bounds write in lwIP TCP/IP Stack MQTT Client ApplicationEPSS 0.5%CVE-2026-53002CRITICALnetfilter: conntrack: remove sprintf usageEPSS 0.5%CVE-2026-65374HIGHA memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahEPSS 0.5%CVE-2024-28318HIGHgpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swEPSS 0.5%CVE-2026-45813HIGHApache NimBLE: Incorrect data validation in BASS add/modify source operationEPSS 0.5%CVE-2023-52727HIGHOpen Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.EPSS 0.5%CVE-2025-20727HIGHIn Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE EPSS 0.5%