Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-27227CRITICALA malicious DNS response can trigger a number of OOB reads, writes, and other memory issuesEPSS 0.3%CVE-2023-25880HIGHZDI-CAN-19412: Adobe Dimension GLTF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2020-18900LOWA heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor hEPSS 0.3%CVE-2022-31696HIGHVMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local acceEPSS 0.3%CVE-2026-7354HIGHOut of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2022-41686MEDIUMOut-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The proc ...EPSS 0.3%CVE-2023-34305HIGHAshlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-43040HIGHGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2026-47314HIGHOut-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5daEPSS 0.3%CVE-2022-45587MEDIUMStack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.EPSS 0.3%CVE-2024-24920HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2024-23795HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2023-47063HIGHAdobe Illustrator 2023 CC 27.7 Memory Corruption Out-Of-Bounds-Write Vulnerability IV.EPSS 0.3%CVE-2024-24924HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2024-24922HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2022-28667MEDIUMOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially eEPSS 0.3%CVE-2023-47046MEDIUMZDI-CAN-21684: Adobe Audition MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-3086HIGHGStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-44330HIGHAdobe Photoshop 2023 CC 24.7 Memory Corruption Vulnerability III.EPSS 0.3%