Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2024-32504HIGHAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, EEPSS 0.2%CVE-2026-88051HIGHTesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fieldsEPSS 0.2%CVE-2026-28662HIGHIn p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead tEPSS 0.2%CVE-2026-63276MEDIUMStack buffer overflow in CFF to Type 1 font conversionEPSS 0.2%CVE-2026-8356MEDIUMStack buffer overflow in PPT presentation importEPSS 0.2%CVE-2026-17029HIGHIBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets ExtensionEPSS 0.2%CVE-2026-3842HIGHQemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writeEPSS 0.2%CVE-2022-42503MEDIUMIn ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing EPSS 0.2%CVE-2026-84511HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27,EPSS 0.2%CVE-2021-26383HIGHInsufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a comEPSS 0.2%CVE-2026-44637HIGHlibsixel: integer overflow in parserEPSS 0.2%CVE-2026-20481MEDIUMIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.2%CVE-2026-20497MEDIUMIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.2%CVE-2026-20466MEDIUMIn sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, ifEPSS 0.2%CVE-2026-58106LOWIncomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocationEPSS 0.2%CVE-2026-84611HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2026-16936HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-20477MEDIUMIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2026-20475MEDIUMIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2023-32466MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with higEPSS 0.2%