Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-5643HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2024-20040HIGHIn wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilegEPSS 0.2%CVE-2026-65704HIGHFFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten DecoderEPSS 0.2%CVE-2024-2971LOWOut-of-bounds array access due to negative object numbers in indirect references in Xpdf 4.05EPSS 0.2%CVE-2019-25550MEDIUMEncrypt PDF 2.3 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2022-42505MEDIUMIn ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrectEPSS 0.2%CVE-2022-42506MEDIUMIn SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local EPSS 0.2%CVE-2022-42504MEDIUMIn CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This coulEPSS 0.2%CVE-2016-20038HIGHyTree 1.94-1.1 Stack-Based Buffer OverflowEPSS 0.2%CVE-2022-33730MEDIUMHeap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical aEPSS 0.2%CVE-2026-71974MEDIUMU-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition ReadEPSS 0.2%CVE-2026-10669HIGHXtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationEPSS 0.2%CVE-2025-9340NONEnative encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.EPSS 0.2%CVE-2018-25266MEDIUMAngry IP Scanner 3.5.3 Denial of Service via Preferences Buffer OverflowEPSS 0.2%CVE-2026-21307HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-88053HIGHTesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddataEPSS 0.2%CVE-2023-0186MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of EPSS 0.2%CVE-2024-22448MEDIUMDell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploiEPSS 0.2%CVE-2021-46779HIGHInsufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASPEPSS 0.2%CVE-2018-25215MEDIUMExcel Password Recovery Professional 8.2.0.0 Local Buffer Overflow DoSEPSS 0.2%