Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-7980HIGHAshlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7260HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-42262HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may leaEPSS 0.2%CVE-2023-32155HIGHTesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-0874HIGHCATPART File Parsing Out-of-Bounds WriteEPSS 0.2%CVE-2017-20228HIGHFlat Assembler 1.71.21 Stack-Based Buffer Overflow ROPEPSS 0.2%CVE-2026-0875HIGHMODEL File Parsing Out-of-Bounds WriteEPSS 0.2%CVE-2023-30382HIGHA buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilegeEPSS 0.2%CVE-2025-49530HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-49526HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43594HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43548HIGHDimension | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-27197HIGHLightroom Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-38610HIGHA memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An apEPSS 0.2%CVE-2025-43569HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43554HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-7923HIGHOut of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2025-1122MEDIUMOut-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gaEPSS 0.2%CVE-2024-20081CRITICALIn gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege EPSS 0.2%CVE-2019-25629HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via LoggingEPSS 0.2%