Weaknesses of type CWE-787

5,155 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-46347HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.5%CVE-2022-22752HIGHMozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence EPSS 0.5%CVE-2023-23606HIGHMemory safety bugs fixed in Firefox 109EPSS 0.5%CVE-2022-24893HIGHEspressif Bluetooth Mesh Stack Vulnerable to Out-of-bounds Write leading to memory buffer corruptionEPSS 0.5%CVE-2024-6820HIGHIrfanView AWD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6822HIGHIrfanView CIN File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6819HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-31963HIGHHTSlib CRAM reader has heap buffer overflow due to improper validation of inputEPSS 0.5%CVE-2023-25671HIGHTensorFlow has segmentation fault in tfg-translate EPSS 0.5%CVE-2026-31971HIGHHTSlib CRAM decoder vulnerable to buffer overflowEPSS 0.5%CVE-2026-31968HIGHHTSlib CRAM decoder vulnerable to buffer overflowEPSS 0.5%CVE-2026-31969HIGHHTSlib CRAM decoder has a heap buffer overflowEPSS 0.5%CVE-2022-20769HIGHCisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service VulnerabilityEPSS 0.5%CVE-2023-26555MEDIUMpraecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipEPSS 0.5%CVE-2023-42869HIGHMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPaEPSS 0.5%CVE-2026-21869HIGHllama.cpp has Out-of-bounds Write in llama-serverEPSS 0.5%CVE-2026-64739HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.5%CVE-2023-44197HIGHJunos OS and Junos OS Evolved: An rpd crash may occur when BGP is processing newly learned routesEPSS 0.5%CVE-2023-46760HIGHOut-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46761—Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%