Weaknesses of type CWE-787

5,210 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2020-9695HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-35976HIGHxsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RINGEPSS 0.3%CVE-2018-25211HIGHAllok Video Splitter 3.1.1217 Buffer Overflow via License NameEPSS 0.3%CVE-2024-56615HIGHbpf: fix OOB devmap writes when deleting elementsEPSS 0.3%CVE-2024-20148CRITICALIn wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) codeEPSS 0.3%CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2025-10900HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-10899HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-10888HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-10898HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-54210HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2021-33124MEDIUMOut-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aesEPSS 0.3%CVE-2024-43097HIGHIn resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation EPSS 0.3%CVE-2025-54213HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2019-25631HIGHAIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2019-25633HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2024-23234HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, EPSS 0.3%CVE-2026-35195MEDIUMWasmtime has an out-of-bounds write or crash when transcoding component model stringsEPSS 0.3%CVE-2026-68967HIGHOut-of-bounds Write in Bendix EC80 Brake ECUEPSS 0.3%CVE-2026-48427HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.3%