Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-2923HIGHGStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-12522HIGHStack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fieldsEPSS 0.3%CVE-2021-43018HIGHAdobe Photoshop JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-4090—An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1]EPSS 0.3%CVE-2022-44318MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpreEPSS 0.3%CVE-2024-12671HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2022-46348HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.3%CVE-2023-48632HIGHZDI-CAN-22172: Adobe After Effects AEP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-49295HIGHlibde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPSEPSS 0.3%CVE-2026-11604MEDIUMAn incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authentiEPSS 0.3%CVE-2024-1847HIGHMultiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.3%CVE-2022-46346HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.3%CVE-2024-6442MEDIUMBluetooth: ASCS Unchecked tailroom of the response bufferEPSS 0.3%CVE-2018-7517—In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability.EPSS 0.3%CVE-2022-43071MEDIUMA stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via EPSS 0.3%CVE-2022-47521HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/micEPSS 0.3%CVE-2025-1938MEDIUMMemory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8EPSS 0.3%CVE-2024-4467HIGHQemu-kvm: 'qemu-img info' leads to host file read/writeEPSS 0.3%CVE-2025-53855HIGHAn out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadeEPSS 0.3%CVE-2025-21161HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.3%