Weaknesses of type CWE-787

5,205 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-0686MEDIUMGrub2: romfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading datEPSS 0.3%CVE-2026-11037CRITICALOut of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.3%CVE-2026-62653HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol thEPSS 0.3%CVE-2025-10882HIGHX_T File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-0685MEDIUMGrub2: jfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading dataEPSS 0.3%CVE-2023-32201HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.3%CVE-2022-47086MEDIUMGPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.cEPSS 0.3%CVE-2023-31284HIGHillumos illumos-gate before 676abcb has a stack buffer overflow in /dev/net, leading to privilege escalation via a stat on a long file name EPSS 0.3%CVE-2026-0126HIGHIn WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additioEPSS 0.3%CVE-2024-23270HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma EPSS 0.3%CVE-2026-0159HIGHIn Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no aEPSS 0.3%CVE-2026-0170HIGHIn Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote EPSS 0.3%CVE-2026-0148HIGHIn multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could leadEPSS 0.3%CVE-2023-4754MEDIUMOut-of-bounds Write in gpac/gpacEPSS 0.3%CVE-2026-0147HIGHIn __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. ThiEPSS 0.3%CVE-2026-0146HIGHIn mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This coulEPSS 0.3%CVE-2022-42946HIGHParsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in EPSS 0.3%CVE-2026-10114MEDIUMOpen5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds writeEPSS 0.3%CVE-2024-47963HIGHOut-of-bounds Write vulnerability in Delta Electronics CNCSoft-G2EPSS 0.3%