Weaknesses of type CWE-787

5,226 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2025-54517HIGHOut of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.EPSS 0.1%CVE-2026-47511HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-boundsEPSS 0.1%CVE-2026-47501HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supEPSS 0.1%CVE-2019-25661MEDIUMRemote Process Explorer 1.0.0.16 Local Buffer Overflow DoSEPSS 0.1%CVE-2025-32022MEDIUMFinit has heap based buffer overwrite in urandom.so pluginEPSS 0.1%CVE-2026-60063HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2026-20476MEDIUMIn ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User executioEPSS 0.1%CVE-2025-58150HIGHx86: buffer overrun with shadow paging + tracingEPSS 0.1%CVE-2026-70628HIGHFFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV FileEPSS 0.1%CVE-2016-20042HIGHTRN 3.6-23 Stack Buffer Overflow Local Code ExecutionEPSS 0.1%CVE-2024-45555HIGHInteger Overflow to Buffer Overflow in Automotive OS PlatformEPSS 0.1%CVE-2026-20478MEDIUMIn Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User exEPSS 0.1%CVE-2023-22351MEDIUMOut-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege EPSS 0.1%CVE-2019-25612HIGHAdmin Express 1.2.5.485 Local SEH Buffer Overflow via Folder PathEPSS 0.1%CVE-2026-102474MEDIUMDash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservationEPSS 0.1%CVE-2026-4407LOWOut-of-bounds array write in Xpdf 4.06 due to missing validationEPSS 0.1%CVE-2026-18374MEDIUMPassing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library versioEPSS 0.1%CVE-2025-39818HIGHHID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs saveEPSS 0.1%CVE-2024-45382LOWLiteos_a has an Out-of-bounds Write vulnerabilityEPSS 0.1%CVE-2026-24201MEDIUMNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successfulEPSS 0.1%