Weaknesses of type CWE-787

5,157 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-34589HIGHOpenEXR: DWA Lossy Decoder Heap Out-of-Bounds WriteEPSS 0.5%CVE-2026-17264MEDIUMMedixant RadiAnt DICOM Out-of-bounds writeEPSS 0.5%CVE-2024-23120HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2026-45770HIGHSuricata lua: excessive flow variable registration can bypass sandboxEPSS 0.5%CVE-2024-45539HIGHOut-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology EPSS 0.5%CVE-2026-34195HIGHGPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexesEPSS 0.5%CVE-2026-43815HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.5%CVE-2026-84444HIGHlibheif uncompressed tiled image encoding allows out-of-bounds writeEPSS 0.5%CVE-2025-2750MEDIUMOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds writeEPSS 0.5%CVE-2023-39485HIGHPDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-17272HIGHIBM i is Affected By a Denial of Service in HTTP Server []EPSS 0.5%CVE-2026-28972MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 andEPSS 0.5%CVE-2026-86882MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.5%CVE-2026-57021MEDIUMJunos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crashEPSS 0.5%CVE-2026-68579HIGHFreeRDP before 3.30.0 Heap Overflow via CliprdrStream_ReadEPSS 0.5%CVE-2022-41902HIGHOut of bounds write in grappler in TensorflowEPSS 0.5%CVE-2021-3696—A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap EPSS 0.5%CVE-2025-0143MEDIUMZoom Workplace Apps for Linux - Out-of-bounds WriteEPSS 0.5%CVE-2026-13087HIGHKernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...EPSS 0.5%CVE-2024-23969HIGHChargePoint Home Flex wlanchnllst Out-Of-Bounds WriteEPSS 0.5%