Weaknesses of type CWE-787

5,158 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-19437HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2021-43529CRITICALThunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. ThundeEPSS 0.5%CVE-2026-7322HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2024-12198HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.5%CVE-2023-0054HIGHOut-of-bounds Write in vim/vimEPSS 0.5%CVE-2022-41992HIGHA memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A specially-EPSS 0.5%CVE-2026-93393CRITICALHeap overflow via oversized decrypted TLS record sequence in Windows Secure Channel streamEPSS 0.5%CVE-2026-5066MEDIUMnet: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect functionEPSS 0.5%CVE-2024-28562MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::cEPSS 0.5%CVE-2026-85670HIGHtokenizers BpeBuilder Buffer Overflow via merge tokenEPSS 0.5%CVE-2026-68806HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-62871HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-43210MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, mEPSS 0.5%CVE-2026-8388MEDIUMIncorrect boundary conditions in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2021-3695—A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heaEPSS 0.5%CVE-2026-65395MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.5%CVE-2026-34379HIGHOpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)EPSS 0.5%CVE-2026-28956MEDIUMA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.EPSS 0.5%CVE-2025-5269HIGHMemory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11EPSS 0.5%CVE-2021-3546—An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including EPSS 0.5%