Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-7950MEDIUMOut of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via maEPSS 0.2%CVE-2026-59181MEDIUMOpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElementsEPSS 0.2%CVE-2016-20043HIGHNRSS RSS Reader 0.3.9-1 Stack Buffer OverflowEPSS 0.2%CVE-2024-37676HIGHAn issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.EPSS 0.2%CVE-2024-7671HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2018-25256MEDIUMIP TOOLS 2.50 Local Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-1335HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.2%CVE-2026-47747HIGHstable-diffusion.cpp has a Heap-based Buffer OverflowEPSS 0.2%CVE-2026-70632HIGHFFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI DemuxingEPSS 0.2%CVE-2026-81878MEDIUMradare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parserEPSS 0.2%CVE-2023-39427HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%CVE-2024-48241MEDIUMAn issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.EPSS 0.2%CVE-2025-2631HIGHOut of Bounds Write Vulnerability in NI LabVIEW in InitCPUInformation()EPSS 0.2%CVE-2026-47750HIGHstable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint filesEPSS 0.2%CVE-2026-50264HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformatEPSS 0.2%CVE-2025-2632HIGHOut of Bounds Write Vulnerability in NI LabVIEW reading CPU info from cacheEPSS 0.2%CVE-2026-0954HIGHOut-Of-Bounds Write When Opening a Corrupt DSB File in Digilent DASYLabEPSS 0.2%CVE-2026-46331HIGHnet/sched: fix pedit partial COW leading to page cache corruptionEPSS 0.2%CVE-2024-56784HIGHdrm/amd/display: Adding array index check to prevent memory corruptionEPSS 0.2%CVE-2023-39943HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%