Weaknesses of type CWE-787

5,203 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-27873MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 andEPSS 0.3%CVE-2026-0171HIGHIn multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution wiEPSS 0.3%CVE-2026-1284HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.3%CVE-2022-32944HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOEPSS 0.3%CVE-2023-34325HIGHMultiple vulnerabilities in libfsimage disk handlingEPSS 0.3%CVE-2023-45734MEDIUMDsoftbus has an out-of-bounds write vulnerabilityEPSS 0.3%CVE-2026-21897HIGHCryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_ParametersEPSS 0.3%CVE-2022-42947HIGHA maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerEPSS 0.3%CVE-2026-67549HIGHOpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds writeEPSS 0.3%CVE-2026-55737MEDIUMHeap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoderEPSS 0.3%CVE-2025-9456HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2022-1943—A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation wEPSS 0.3%CVE-2026-10999MEDIUMInteger overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2018-25230MEDIUMFree IP Switcher 3.1 Denial of Service via Computer NameEPSS 0.3%CVE-2025-9452HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2022-43045MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manEPSS 0.3%CVE-2022-32820HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11EPSS 0.3%CVE-2026-48040MEDIUMnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessEPSS 0.3%CVE-2024-46919MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to EPSS 0.3%CVE-2024-20057HIGHIn keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.3%