Weaknesses of type CWE-787

5,159 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-62818CRITICALAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.5%CVE-2026-79131CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandboxEPSS 0.5%CVE-2026-79138CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-5733HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.5%CVE-2026-79189CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-85050CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46274HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.EPSS 0.5%CVE-2026-79043CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-87621CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-79019CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2024-46264HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.EPSS 0.5%CVE-2026-87438CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46267HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.EPSS 0.5%CVE-2024-46263HIGHcute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.EPSS 0.5%CVE-2026-79188CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-87638CRITICALOut of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2024-46276HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.EPSS 0.5%CVE-2024-46259HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.EPSS 0.5%CVE-2023-38072HIGHA vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), TeamcenEPSS 0.5%CVE-2026-5735HIGHMemory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.5%