Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-0536HIGHGIF File Parsing Stack Based Buffer OverflowEPSS 0.2%CVE-2022-21172MEDIUMOut of bounds write for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable escalation of privilegEPSS 0.2%CVE-2022-50368HIGHdrm/msm/dsi: fix memory corruption with too many bridgesEPSS 0.2%CVE-2018-25260HIGHMAGIX Music Editor 3.1 Buffer Overflow via SEHEPSS 0.2%CVE-2019-25619HIGHFTP Shell Server 6.83 Buffer Overflow via Account NameEPSS 0.2%CVE-2025-21165HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-21166HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-21504MEDIUMHeap Buffer Overflow in iccDEV ToneMap ParserEPSS 0.2%CVE-2026-11690HIGHOut of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2025-21164HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-53098HIGHdrm/xe/ufence: Prefetch ufence addr to catch bogus addressEPSS 0.2%CVE-2024-32668HIGHbhyve(8) privileged guest escape via USB controllerEPSS 0.2%CVE-2025-64503MEDIUM[BIGSLEEP-434615384] cups-filters 1.x: out of bounds write in pdftorasterEPSS 0.2%CVE-2026-41970MEDIUMOut-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect avEPSS 0.2%CVE-2024-45183MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leadsEPSS 0.2%CVE-2024-55413HIGHA vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arEPSS 0.2%CVE-2025-54284HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-21131HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-31602MEDIUMNVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploEPSS 0.2%CVE-2025-21132HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%