Weaknesses of type CWE-787

5,177 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-41186—Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from uEPSS 0.4%CVE-2023-38089HIGHKofax Power PDF clearInterval Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-37006HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2026-16958MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2022-42941HIGHA malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by reaEPSS 0.4%CVE-2026-17255MEDIUMIBM i is Affected By Denial of Service Vulnerability []EPSS 0.4%CVE-2026-59091HIGHGimp: gimp: multiple vulnerabilities in file format plugins via crafted image fileEPSS 0.4%CVE-2024-10397HIGHPreallocated buffer overflows in XDR responsesEPSS 0.4%CVE-2025-26598HIGHXorg: xwayland: out-of-bounds write in createpointerbarrierclient()EPSS 0.4%CVE-2026-59184HIGHOpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB writeEPSS 0.4%CVE-2026-59679CRITICALfs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2EPSS 0.4%CVE-2026-78952HIGHOut of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the rendEPSS 0.4%CVE-2026-43677MEDIUMAn out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8,EPSS 0.4%CVE-2023-5405MEDIUMServer information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. SEPSS 0.4%CVE-2026-7899HIGHOut of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2026-43761MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, EPSS 0.4%CVE-2024-39890HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200,EPSS 0.4%CVE-2022-0135—An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a EPSS 0.4%CVE-2026-1788MEDIUMBuffer Overflow in Xquic ServerEPSS 0.4%CVE-2023-4280CRITICALUnvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory regionEPSS 0.4%