Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-49522HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-8901HIGHOut of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via aEPSS 0.3%CVE-2026-2674MEDIUMOut-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers.EPSS 0.3%CVE-2019-25679HIGHRealTerm Serial Terminal 2.0.0.70 Buffer Overflow SEHEPSS 0.3%CVE-2026-20644MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.3%CVE-2010-3843—The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this EPSS 0.3%CVE-2025-32403MEDIUMAn Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the libraryEPSS 0.3%CVE-2025-32404MEDIUMAn Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the libraryEPSS 0.3%CVE-2022-43653HIGHBentley View SKP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-23148HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2022-45332HIGHLibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.EPSS 0.3%CVE-2026-12633HIGHOut-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router AdvertisementEPSS 0.3%CVE-2025-12768HIGHFactoryTalk® Historian Machine Edition - Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2022-22063HIGHMemory corruption in CoreEPSS 0.3%CVE-2025-48499MEDIUMOut-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (EPSS 0.3%CVE-2022-41283HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamcenEPSS 0.3%CVE-2024-9735HIGHTungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-32706HIGHPX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packetEPSS 0.3%CVE-2025-14332HIGHMemory safety bugs fixed in Firefox 146 and Thunderbird 146EPSS 0.3%CVE-2024-9737HIGHTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%