Weaknesses of type CWE-787

5,210 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-0957HIGHOut-Of-Bounds Write in Digilent DASYLabEPSS 0.2%CVE-2023-22327MEDIUMOut-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable inforEPSS 0.2%CVE-2025-24444HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-24445HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-24441HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22612HIGHAn issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler wiEPSS 0.2%CVE-2025-24442HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-47317HIGHOut-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitraEPSS 0.2%CVE-2024-53193HIGHclk: clk-loongson2: Fix memory corruption bug in struct loongson2_clk_providerEPSS 0.2%CVE-2025-21919HIGHsched/fair: Fix potential memory corruption in child_cfs_rq_on_listEPSS 0.2%CVE-2019-25660MEDIUMLanHelper 1.74 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2021-25492HIGHLack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.EPSS 0.2%CVE-2024-11920MEDIUMInappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memorEPSS 0.2%CVE-2025-61831HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-32539HIGHHorner Automation Cscape Out-of-bounds WriteEPSS 0.2%CVE-2024-22103MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%CVE-2024-54520MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura EPSS 0.2%CVE-2023-32203HIGHHorner Automation Cscape Out-of-bounds WriteEPSS 0.2%CVE-2017-13313HIGHIn ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due tEPSS 0.2%CVE-2026-8357MEDIUMHeap buffer overflow in Calc formula compilationEPSS 0.2%