Weaknesses of type CWE-787

5,182 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2018-9478CRITICALIn process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds chEPSS 0.4%CVE-2023-2457HIGHOut of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially eEPSS 0.4%CVE-2022-42370HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2018-9479CRITICALIn process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds chEPSS 0.4%CVE-2022-42394HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-43712MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.4%CVE-2026-43676MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2026-10027HIGHIBM MQ queue manager is vulnerable to unauthenticated remote code executionEPSS 0.4%CVE-2022-35897MEDIUMAn stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.EPSS 0.4%CVE-2022-29208HIGHSegfault and Out-of-bounds Write write due to incomplete validation in TensorFlowEPSS 0.4%CVE-2022-35095MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.EPSS 0.4%CVE-2025-22883HIGHISPSoft File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-19387HIGHGstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoderEPSS 0.4%CVE-2022-41308HIGHA maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by reEPSS 0.4%CVE-2022-30426HIGHThere is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An atEPSS 0.4%CVE-2026-47151HIGHDoor Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2EPSS 0.4%CVE-2022-35097MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.EPSS 0.4%CVE-2021-46879HIGHAn issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in EPSS 0.4%CVE-2026-47150HIGHIAS Zone enroll invalid table index and write in EmberZNet 9.0.2EPSS 0.4%