Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-49614MEDIUMOut of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclEPSS 0.2%CVE-2026-68514MEDIUMOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep imagesEPSS 0.2%CVE-2026-12927HIGHCWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a maliciousEPSS 0.2%CVE-2026-61714HIGHFluidSynth: Heap Buffer Overflow in MIDI PlayerEPSS 0.2%CVE-2026-42953HIGHOut-of-bounds write in Labcenter ProteusEPSS 0.2%CVE-2024-23497CRITICALOut-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow anEPSS 0.2%CVE-2019-25589MEDIUMZOC Terminal 7.23.4 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-88052HIGHTesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronizationEPSS 0.2%CVE-2025-6033HIGHMemory Corruption issue in XML_Serialize() in NI Circuit Design SuiteEPSS 0.2%CVE-2019-25565MEDIUMMagic Iso Maker 5.5 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2019-25567MEDIUMValentina Studio 9.0.5 Linux Buffer Overflow via Host FieldEPSS 0.2%CVE-2026-20407CRITICALIn wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilEPSS 0.2%CVE-2019-25637HIGHX-NetStat Pro 5.63 Local Buffer Overflow via EggHunterEPSS 0.2%CVE-2025-1471HIGHEclipse OMR: Buffer overflow vulnerabilityEPSS 0.2%CVE-2019-25650HIGHRiver Past CamDo 3.7.6 Structured Exception Handler Buffer OverflowEPSS 0.2%CVE-2024-43096HIGHIn build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proEPSS 0.2%CVE-2019-25566MEDIUMTransMac 12.3 Denial of Service via Volume Name FieldEPSS 0.2%CVE-2023-32840HIGHIn modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.2%CVE-2026-47178MEDIUMlibheif has Heap Out Of Bounds Write in unci subsystemEPSS 0.2%CVE-2018-25271MEDIUMTextpad 8.1.2 Denial of Service via Run CommandEPSS 0.2%