Weaknesses of type CWE-787

5,182 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-17476MEDIUMIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2026-28618HIGHIn dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no EPSS 0.4%CVE-2021-31837HIGHOut of bounds write vulnerability in McAfee GetSuspEPSS 0.4%CVE-2022-44898HIGHThe MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, anEPSS 0.4%CVE-2022-34260HIGHAdobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-20009HIGHIn alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privileEPSS 0.4%CVE-2024-41443MEDIUMA stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.4%CVE-2025-4124HIGHISPSoft File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-4125HIGHISPSoft File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-41439MEDIUMA heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS)EPSS 0.4%CVE-2026-0263HIGHPAN-OS: Remote Code Execution (RCE) in IKEv2 ProcessingEPSS 0.4%CVE-2026-49879HIGHIn multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execuEPSS 0.4%CVE-2026-56974HIGHIn Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remEPSS 0.4%CVE-2026-58683HIGHIn IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code executiEPSS 0.4%CVE-2022-41180—Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2021-36535MEDIUMBuffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorEPSS 0.4%CVE-2026-56997HIGHIn Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote EPSS 0.4%CVE-2026-56942HIGHIn ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalEPSS 0.4%CVE-2022-39808—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%