Weaknesses of type CWE-787

5,180 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-52988HIGHAnimate | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2026-43745MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2024-11512HIGHIrfanView WBZ Plugin WB1 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-25442HIGHAn issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via paEPSS 0.4%CVE-2026-34971CRITICALWasmtime miscompiled guest heap access enables sandbox escape on aarch64 CraneliftEPSS 0.4%CVE-2022-36039HIGHOut-of-bounds write when parsing DEX files in RizinEPSS 0.4%CVE-2022-42847HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to EPSS 0.4%CVE-2022-42840HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.EPSS 0.4%CVE-2023-48229HIGHOut-of-bounds write in the radio driver for Contiki-NG nRF platformsEPSS 0.4%CVE-2022-41310HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2023-0972CRITICALBuffer overflow in S0 Decryption on Z/IP GatweayEPSS 0.4%CVE-2023-23456MEDIUMUpx: heap-buffer-overflow in packtmt::pack()EPSS 0.4%CVE-2023-39500HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-42373HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-42400HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-42395HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2018-25154HIGHGNU Barcode 0.99 Buffer Overflow in Code 93 Encoding MechanismEPSS 0.4%CVE-2022-42371HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-71255HIGHnanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()EPSS 0.4%CVE-2022-41148HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%