Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-47750HIGHstable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint filesEPSS 0.2%CVE-2023-49128HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounEPSS 0.2%CVE-2018-9413HIGHIn handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remEPSS 0.2%CVE-2023-39431HIGHSantesoft Sante DICOM Viewer Pro Out-of-bounds WriteEPSS 0.2%CVE-2018-25268HIGHLanSpy 2.0.1.159 Local Buffer Overflow via Scan FieldEPSS 0.2%CVE-2025-21650HIGHnet: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issueEPSS 0.2%CVE-2021-3721MEDIUMA denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local accEPSS 0.2%CVE-2021-29566LOWHeap OOB access in `Dilation2DBackpropInput`EPSS 0.2%CVE-2022-29277HIGHIncorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmEPSS 0.2%CVE-2024-0429HIGHBuffer overflow vulnerability on Hex WorkshopEPSS 0.2%CVE-2021-29603LOWHeap OOB write in TFLiteEPSS 0.2%CVE-2019-25712MEDIUMBlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration KeyEPSS 0.2%CVE-2023-49675HIGHCODESYS: Out-of-bounds write through corrupted project filesEPSS 0.2%CVE-2022-29276HIGHSMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading toEPSS 0.2%CVE-2025-6633HIGHRBG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2024-56740HIGHnfs/localio: must clear res.replen in nfs_local_read_doneEPSS 0.2%CVE-2022-30771HIGHInitialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm cEPSS 0.2%CVE-2022-30772HIGHManipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of EPSS 0.2%CVE-2026-47626HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write.EPSS 0.2%CVE-2026-21678HIGHiccDEV has heap-buffer-overflow vulnerability on IccTagXml()EPSS 0.2%