Weaknesses of type CWE-787

5,155 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-7970HIGHOut of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.5%CVE-2022-31902MEDIUMNotepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().EPSS 0.5%CVE-2026-50161CRITICALlibre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflowEPSS 0.5%CVE-2025-30276MEDIUMQsync CentralEPSS 0.5%CVE-2024-43688HIGHcron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE:EPSS 0.5%CVE-2026-8526HIGHOut of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox EPSS 0.5%CVE-2026-8524HIGHOut of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandboEPSS 0.5%CVE-2023-45681HIGHOut of bounds heap buffer write in stb_vorbisEPSS 0.5%CVE-2026-7951HIGHOut of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox vEPSS 0.5%CVE-2023-45676HIGHMulti-byte write heap buffer overflow in start_decoder in stb_vorbisEPSS 0.5%CVE-2025-25898HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. This vEPSS 0.5%CVE-2025-25901HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/EPSS 0.5%CVE-2026-70457HIGHrsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()EPSS 0.5%CVE-2026-41157CRITICALGPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3DEPSS 0.5%CVE-2025-25897HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vuEPSS 0.5%CVE-2024-6820HIGHIrfanView AWD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-29551HIGHMemory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2023-23606HIGHMemory safety bugs fixed in Firefox 109EPSS 0.5%CVE-2022-28288HIGHMozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present iEPSS 0.5%CVE-2024-6818HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%