Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-40363MEDIUMA buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cEPSS 0.4%CVE-2023-28478HIGHTP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.EPSS 0.3%CVE-2024-30282HIGHAdobe Animate 2024 Out of Bound Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-26519HIGHmusl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusEPSS 0.3%CVE-2025-54479HIGHBIG-IP PEM vulnerabilityEPSS 0.3%CVE-2025-58096HIGHBIG-IP TMM vulnerabilityEPSS 0.3%CVE-2022-45202HIGHGPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.cEPSS 0.3%CVE-2025-55036HIGHBIG-IP SSL Orchestrator vulnerabilityEPSS 0.3%CVE-2022-47661HIGHGPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_byteEPSS 0.3%CVE-2024-9259HIGHIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9260HIGHIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-1484MEDIUMGlib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode()EPSS 0.3%CVE-2026-20418CRITICALIn Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no EPSS 0.3%CVE-2024-10573MEDIUMMpg123: buffer overflow when writing decoded pcm samplesEPSS 0.3%CVE-2023-42131HIGHAnsys SpaceClaim X_B File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-14420CRITICALOut of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escaEPSS 0.3%CVE-2026-9967CRITICALOut of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a EPSS 0.3%CVE-2026-16807HIGHOut of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape viaEPSS 0.3%CVE-2022-46345HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.3%CVE-2026-16419CRITICALOut of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform aEPSS 0.3%