Weaknesses of type CWE-787

5,210 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-26479LOWDell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploEPSS 0.3%CVE-2026-18393MEDIUMFfmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursorEPSS 0.3%CVE-2024-29786MEDIUMIn pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This couldEPSS 0.3%CVE-2025-54216HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-54218HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-12199HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2026-41678HIGHrust-openssl: Incorrect bounds assertion in aes key wrapEPSS 0.3%CVE-2025-54221HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-44178MEDIUMThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.EPSS 0.3%CVE-2025-54215HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-92869HIGHAn out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.EPSS 0.3%CVE-2022-42255MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lEPSS 0.3%CVE-2026-11090MEDIUMUninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.3%CVE-2022-40103MEDIUMTenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers toEPSS 0.3%CVE-2023-27959HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrEPSS 0.2%CVE-2025-7222HIGHLuxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-1078HIGHA flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the heEPSS 0.2%CVE-2023-2687LOWBuffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heEPSS 0.2%CVE-2024-39378HIGHAudition | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-42858HIGHA memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to exeEPSS 0.2%