Weaknesses of type CWE-787

5,205 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-57961MEDIUMOut-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abEPSS 0.3%CVE-2024-50230HIGHnilfs2: fix kernel bug due to missing clearing of checked flagEPSS 0.3%CVE-2026-75892MEDIUMOut of bounds write in PDP ctx GSN-Address decodeEPSS 0.3%CVE-2024-41864HIGHAdobe Substance 3D Designer ICO Parsing Out-Of-Bounds Write VulnerabilityEPSS 0.3%CVE-2026-35226HIGHOut-of-bounds Write in CODESYS PROFINET ControllerEPSS 0.3%CVE-2024-45144HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-30290HIGHAdobe FrameMaker WEBP File Parsing Out Of Bound WriteEPSS 0.3%CVE-2020-36602MEDIUMThere is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and EPSS 0.3%CVE-2025-24139HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS VeEPSS 0.3%CVE-2026-16886MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2026-11173HIGHOut of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execEPSS 0.3%CVE-2026-25506HIGHMUNGE has a buffer overflow in message unpacking allows key leakage and credential forgeryEPSS 0.3%CVE-2025-24014MEDIUMsegmentation fault in win_line() in Vim < 9.1.1043EPSS 0.3%CVE-2022-43044MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isoEPSS 0.3%CVE-2025-49492HIGHOut-of-bounds write in lte-telephonyEPSS 0.3%CVE-2025-12603LOW/etc/timezone can be Arbitrarily WrittenEPSS 0.3%CVE-2025-12602LOW/etc/avahi/services/z9.service can be Arbitrarily WrittenEPSS 0.3%CVE-2025-10884HIGHCATPART File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2023-32538HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%CVE-2023-32273HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%