Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-37765—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpEPSS 0.3%CVE-2025-52513HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds EPSS 0.3%CVE-2024-52994HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-41304HIGHAn Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK 2020 version and prior may lead to code execution through maliciously crafted FBX fEPSS 0.3%CVE-2025-20633HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) cEPSS 0.3%CVE-2024-49538HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-40919MEDIUMGimp: gimp: denial of service via specially crafted seattle filmworks fileEPSS 0.3%CVE-2023-42926HIGHMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliEPSS 0.3%CVE-2024-49544HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-81738LOWOpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEPSS 0.3%CVE-2023-37767—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/EPSS 0.3%CVE-2026-4450HIGHOut of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.3%CVE-2026-4459HIGHOut of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corrEPSS 0.3%CVE-2026-4440HIGHOut of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2026-84588MEDIUMA memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciouslyEPSS 0.3%CVE-2023-31910HIGHJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at /jerrEPSS 0.3%CVE-2023-47041HIGHZDI-CAN-21697: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11577HIGHLuxion KeyShot SKP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11579HIGHLuxion KeyShot OBJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-20458HIGHIn Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE haEPSS 0.3%