Weaknesses of type CWE-787

5,212 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-65086HIGHOut-of-bounds write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2024-4976LOWOut-of-bounds array write in Xpdf 4.05 due to missing object type checkEPSS 0.2%CVE-2026-43774MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2023-21085HIGHIn nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remoteEPSS 0.2%CVE-2024-22273HIGHThe storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access tEPSS 0.2%CVE-2025-11795HIGHJPG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2024-38665MEDIUMOut-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.2%CVE-2016-20050MEDIUMNetSchedScan 1.0 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2023-32466MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with higEPSS 0.2%CVE-2026-49839HIGHjq --rawfile invalid-state reuse after String too long causes heap-buffer-overflowEPSS 0.2%CVE-2026-21305HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-62291MEDIUMlibheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensionsEPSS 0.2%CVE-2026-10643HIGHOut-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)EPSS 0.2%CVE-2024-27370MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-64725HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.2%CVE-2024-27383MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2026-59948HIGHComposer: Arbitrary file write outside vendor via malicious transitive package nameEPSS 0.2%CVE-2025-53705HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Out-of-bounds WriteEPSS 0.2%CVE-2024-27373MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%