Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2019-25637HIGHX-NetStat Pro 5.63 Local Buffer Overflow via EggHunterEPSS 0.2%CVE-2022-20600HIGHIn TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with SysteEPSS 0.2%CVE-2026-13215MEDIUMZephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem imageEPSS 0.2%CVE-2026-14986MEDIUMOut-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transactionEPSS 0.2%CVE-2024-24581MEDIUMArkcompiler runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-71969HIGHOP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt OperationsEPSS 0.2%CVE-2026-42250MEDIUMOff-by-One Leading to Out-of-Bounds Write in bzip2EPSS 0.2%CVE-2026-45253HIGHMissing validation in ptrace(PT_SC_REMOTE)EPSS 0.2%CVE-2023-33877LOWOut-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticateEPSS 0.2%CVE-2022-20577MEDIUMIn OemSimAuthRequest::encode of wlandata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 0.2%CVE-2022-20509MEDIUMIn mapGrantorDescr of MessageQueueBase.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local esEPSS 0.2%CVE-2021-46791MEDIUMInsufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binarEPSS 0.2%CVE-2021-46772LOWInsufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the strucEPSS 0.2%CVE-2022-20564MEDIUMIn _ufdt_output_strtab_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead tEPSS 0.2%CVE-2018-25267MEDIUMUltraISO 9.7.1.3519 Buffer Overflow via Output FileNameEPSS 0.2%CVE-2022-20569MEDIUMIn thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This coEPSS 0.2%CVE-2022-20576MEDIUMIn externalOnRequest of rilapplication.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local EPSS 0.2%CVE-2022-20596MEDIUMIn sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.2%CVE-2019-25561MEDIUMLyric Maker 2.0.1.0 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2022-20579MEDIUMIn RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could leaEPSS 0.2%