Weaknesses of type CWE-787

5,202 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-30414MEDIUMJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.EPSS 0.3%CVE-2022-44513HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-11928CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2023-30410MEDIUMJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-functEPSS 0.3%CVE-2024-39390HIGHAdobe Indesign 2024 DOC File Parsing Memory CorruptionEPSS 0.3%CVE-2024-39394HIGHAdobe Indesign 2024 PDF File Parsing Out Of Bound Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-13873MEDIUMOut of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2022-31610HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabiEPSS 0.3%CVE-2021-39822HIGHAdobe InDesign BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21595HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-1276HIGHDWG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2022-32866HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS MontereEPSS 0.3%CVE-2026-20432HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.3%CVE-2025-57807LOWImageMagick BlobStream Forward-Seek Under-AllocationEPSS 0.3%CVE-2026-6325LOWOut-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listEPSS 0.3%CVE-2023-34823MEDIUMfdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.EPSS 0.3%CVE-2026-100888MEDIUMTrusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c dkim_canon_selecthdrs out-of-bounds writeEPSS 0.3%CVE-2022-3219LOWGnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressEPSS 0.3%CVE-2026-24817HIGHA potential heap-buffer overflow in praydog/UEVREPSS 0.3%CVE-2025-27374MEDIUMAn issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 10EPSS 0.3%