Weaknesses of type CWE-787

5,225 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-54275MEDIUMSubstance3D - Viewer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-25948MEDIUMDell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute aEPSS 0.2%CVE-2025-40762HIGHA vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002).EPSS 0.2%CVE-2026-84523MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2026-75663HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-64195HIGHOut Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper validation of user-supplied dataEPSS 0.2%CVE-2024-25947MEDIUMDell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute aEPSS 0.2%CVE-2026-20468MEDIUMIn apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicEPSS 0.2%CVE-2026-84552MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2026-72854MEDIUMmsgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized ReservationEPSS 0.2%CVE-2025-23396HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2024-32909HIGHIn handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of priEPSS 0.2%CVE-2026-41220HIGHLocal privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before buEPSS 0.2%CVE-2025-33190MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit oEPSS 0.2%CVE-2023-53331HIGHpstore/ram: Check start of empty przs during initEPSS 0.2%CVE-2026-53465MEDIUMImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageEPSS 0.2%CVE-2019-25691HIGHFaleemi Desktop Software 1.8 Local Buffer Overflow SEH DEP BypassEPSS 0.2%CVE-2026-53202HIGHaccel/ivpu: Fix signed integer truncation in IPC receiveEPSS 0.2%CVE-2026-0030HIGHIn __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could leadEPSS 0.2%CVE-2022-41597LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%