Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-13216MEDIUMOut-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability lengthEPSS 0.2%CVE-2018-25267MEDIUMUltraISO 9.7.1.3519 Buffer Overflow via Output FileNameEPSS 0.2%CVE-2022-20596MEDIUMIn sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.2%CVE-2022-20579MEDIUMIn RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could leaEPSS 0.2%CVE-2021-46772LOWInsufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the strucEPSS 0.2%CVE-2022-20569MEDIUMIn thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This coEPSS 0.2%CVE-2021-26402HIGHInsufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write parEPSS 0.2%CVE-2025-61859HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafteEPSS 0.2%CVE-2025-2480HIGHSantesoft Sante DICOM Viewer Pro Out-of-bounds WriteEPSS 0.2%CVE-2025-61858HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT fEPSS 0.2%CVE-2019-25648MEDIUMMyVideoConverter Pro 3.14 Denial of Service Buffer OverflowEPSS 0.2%CVE-2026-6676HIGHAvira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archiveEPSS 0.2%CVE-2026-43666MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and EPSS 0.2%CVE-2026-41990MEDIUMLibgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.EPSS 0.2%CVE-2026-45684MEDIUMOpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffersEPSS 0.2%CVE-2024-4141LOWOut-of-bounds array write in Xpdf 4.05 due to incorrect bounds checkEPSS 0.2%CVE-2023-25537MEDIUM Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vuEPSS 0.2%CVE-2018-25253MEDIUMTermite 3.4 Denial of Service via Settings Buffer OverflowEPSS 0.2%CVE-2025-61857HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening speciallyEPSS 0.2%CVE-2022-42521MEDIUMIn encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of EPSS 0.2%