Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-47751HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. OpeningEPSS 0.2%CVE-2026-10644MEDIUMOut-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte bufferEPSS 0.2%CVE-2023-52512MEDIUMpinctrl: nuvoton: wpcm450: fix out of bounds writeEPSS 0.2%CVE-2025-47750HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6MemInIF!set_temp_type_default function. Opening specially crafteEPSS 0.2%CVE-2022-41743HIGHNGINX ngx_http_hls_module vulnerability CVE-2022-41743EPSS 0.2%CVE-2018-25235MEDIUMNetworkActiv Web Server 4.0 Username Field Buffer Overflow DoSEPSS 0.2%CVE-2026-21298HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-71972MEDIUMU-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 DecoderEPSS 0.2%CVE-2026-63419HIGHOpenImageIO: IFF ZBUFFER tile read writes past caller tile bufferEPSS 0.2%CVE-2023-44081HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2026-27622HIGHOpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB writeEPSS 0.2%CVE-2018-25226MEDIUMFTPShell Server 6.83 Denial of Service via Account NameEPSS 0.2%CVE-2018-25228MEDIUMNetSetMan 4.7.1 Workgroup Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2025-7258HIGHIrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7238HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2018-25217HIGHPDF Explorer 1.5.66.2 Structured Exception Handler Local Code ExecutionEPSS 0.2%CVE-2025-7980HIGHAshlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7260HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7231HIGHINVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-42262HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may leaEPSS 0.2%