Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-42521MEDIUMIn encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of EPSS 0.2%CVE-2022-42523MEDIUMIn fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lEPSS 0.2%CVE-2026-41154HIGHGPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_SparseEPSS 0.2%CVE-2025-20631HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.2%CVE-2022-42519MEDIUMIn CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lEPSS 0.2%CVE-2025-20632HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.2%CVE-2022-42525MEDIUMIn fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lEPSS 0.2%CVE-2025-33189HIGHNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit EPSS 0.2%CVE-2023-5912MEDIUM A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2025-23299MEDIUMNVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege accEPSS 0.2%CVE-2026-43904HIGHOpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image widthEPSS 0.2%CVE-2019-25591MEDIUMDNSS Domain Name Search Software 2.1.8 Denial of ServiceEPSS 0.2%CVE-2025-54222HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-64764HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.2%CVE-2026-64763HIGHAn out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 EPSS 0.2%CVE-2022-32266MEDIUMDMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI hanEPSS 0.2%CVE-2024-3900LOWOut-of-bounds stack array write in Xpdf 4.05 due to missing zero checkEPSS 0.2%CVE-2026-65704HIGHFFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten DecoderEPSS 0.2%CVE-2023-5643HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-53720MEDIUMpymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too smallEPSS 0.2%