Weaknesses of type CWE-787

5,182 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-47150HIGHIAS Zone enroll invalid table index and write in EmberZNet 9.0.2EPSS 0.4%CVE-2023-52386HIGHOut-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-35222MEDIUMHiCOS Citizen verification component - Stack Buffer OverflowEPSS 0.4%CVE-2026-34380MEDIUMOpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompressionEPSS 0.4%CVE-2023-52110HIGHThe sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2021-45464HIGHkvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute EPSS 0.4%CVE-2023-22614HIGHAn issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS GuaEPSS 0.4%CVE-2026-41907HIGHuuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is providedEPSS 0.4%CVE-2022-35895HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input paramEPSS 0.4%CVE-2024-44552MEDIUMTenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.EPSS 0.4%CVE-2022-46693HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS EPSS 0.4%CVE-2021-3501—A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, whicEPSS 0.4%CVE-2026-15105MEDIUMdavenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds writeEPSS 0.4%CVE-2026-6681LOWPKCS#7 decode ignores caller output buffer size, writing past buffer boundsEPSS 0.4%CVE-2023-26965MEDIUMloadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.EPSS 0.4%CVE-2023-53372HIGHsctp: fix a potential overflow in sctp_ifwdtsn_skipEPSS 0.4%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.4%CVE-2026-17476MEDIUMIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2024-49823MEDIUMIBM Common Cryptographic Architecture denial of serviceEPSS 0.4%CVE-2026-67549HIGHOpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds writeEPSS 0.4%