Weaknesses of type CWE-787

5,227 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-20493MEDIUMIn wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious acEPSS 0.1%CVE-2026-24201MEDIUMNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successfulEPSS 0.1%CVE-2026-47509MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-boundsEPSS 0.1%CVE-2026-47529MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. EPSS 0.1%CVE-2026-47538MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds writEPSS 0.1%CVE-2025-48518MEDIUMImproper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integEPSS 0.1%CVE-2026-47537MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. EPSS 0.1%CVE-2026-13196HIGHOut-of-bounds Write in KUNBUS piControlEPSS 0.1%CVE-2025-26403MEDIUMOut-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a priviEPSS 0.1%CVE-2025-29949MEDIUMInsufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to wEPSS 0.1%CVE-2026-47532MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-boEPSS 0.1%CVE-2026-63388HIGHLibevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX acceptEPSS 0.1%CVE-2019-25474MEDIUMEasy MP3 Downloader 4.7.8.8 Denial of Service Buffer OverflowEPSS 0.1%CVE-2026-14063MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive informatioEPSS 0.1%CVE-2026-33535MEDIUMImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interactionEPSS 0.1%CVE-2026-17572MEDIUMHDF5 SOHM List Index Heap Buffer OverflowEPSS 0.1%CVE-2026-21362HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2022-32620MEDIUMIn mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution pEPSS 0.1%CVE-2018-25222HIGHSC v7.16 Stack-Based Buffer Overflow Remote Code ExecutionEPSS 0.1%CVE-2022-42501MEDIUMIn HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oEPSS 0.1%