Weaknesses of type CWE-787

5,157 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-46323CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46325CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46324CRITICALSome smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptioEPSS 0.5%CVE-2022-46319CRITICALFingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bouEPSS 0.5%CVE-2021-47719HIGHCNC_Ctrl DllUnregisterServer f5501 Access ViolationEPSS 0.5%CVE-2023-51569HIGHKofax Power PDF BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-21927CRITICALnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()EPSS 0.5%CVE-2026-29774MEDIUMFreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRectsEPSS 0.5%CVE-2021-47705HIGHCNC_Ctrl DllUnregisterServer Access ViolationEPSS 0.5%CVE-2020-21723—A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remoteEPSS 0.5%CVE-2026-10879CRITICALDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersEPSS 0.5%CVE-2026-49840CRITICALFreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingEPSS 0.5%CVE-2026-5187LOWHeap Out-of-Bounds Write in DecodeObjectId() in wolfSSLEPSS 0.5%CVE-2024-41879HIGHRE: New Edge T5 MSRC Case [DCMSFT-1294]EPSS 0.5%CVE-2025-29031CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.EPSS 0.5%CVE-2025-29030CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.EPSS 0.5%CVE-2025-41766HIGHStack buffer overflow on parsing web requestEPSS 0.5%CVE-2025-29029CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.EPSS 0.5%CVE-2025-25372HIGHNASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management ModuleEPSS 0.5%CVE-2026-2807CRITICALMemory safety bugs fixed in Firefox 148 and Thunderbird 148EPSS 0.5%