Weaknesses of type CWE-787

5,210 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-57850HIGHjffs2: Prevent rtime decompress memory corruptionEPSS 0.3%CVE-2022-39143—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2024-45471HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2024-45469HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2018-9470HIGHIn bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote eEPSS 0.3%CVE-2026-102761CRITICALNetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the lEPSS 0.3%CVE-2023-0969LOWGlobal read overflow in Z/IP GatewayEPSS 0.3%CVE-2022-47908HIGHStack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or executeEPSS 0.3%CVE-2023-32804—Mali GPU Userspace Driver can make an Out-of-Bounds accessEPSS 0.3%CVE-2026-18460MEDIUMOff-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.EPSS 0.3%CVE-2023-0249HIGHCVE-2023-0249EPSS 0.3%CVE-2026-12019HIGHHeap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised EPSS 0.3%CVE-2025-47727HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%CVE-2026-40003MEDIUMUSB-based arbitrary memory write vulnerability in ZTE ZX297520V3 soc BootROMEPSS 0.3%CVE-2022-43509HIGHOut-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary codeEPSS 0.3%CVE-2025-47726HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%CVE-2026-12310HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-27933MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 1EPSS 0.3%CVE-2026-12314HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2025-47725HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%