Weaknesses of type CWE-787

5,228 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-47495HIGHNVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bEPSS 0.1%CVE-2026-47498HIGHNVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds writeEPSS 0.1%CVE-2022-25698HIGHMemory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, SnaEPSS 0.1%CVE-2026-88832HIGHBusybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflowEPSS 0.1%CVE-2022-25697HIGHMemory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon Mobile, SnEPSS 0.1%CVE-2026-91815HIGHFoxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.1%CVE-2026-73066MEDIUMTesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddataEPSS 0.1%CVE-2024-0050HIGHIn getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could leadEPSS 0.1%CVE-2025-0034MEDIUMInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_SPATIAL_PART and cauEPSS 0.1%CVE-2022-20546MEDIUMIn getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2026-91142LOWCockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 buildsEPSS 0.1%CVE-2024-25993HIGHIn tmu_reset_tmu_trip_counter of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2024-32855LOWDell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker witEPSS 0.1%CVE-2026-73072HIGHVim: Heap Buffer Overflow when Loading a Spell FileEPSS 0.1%CVE-2025-62862MEDIUMAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorreEPSS 0.1%CVE-2026-33967LOWAn issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driveEPSS 0.1%CVE-2026-33956LOWAn issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to EPSS 0.1%CVE-2026-18086MEDIUMIBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets ExtensionEPSS 0.1%CVE-2025-20656MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2026-55693MEDIUMVim: Out-of-bounds Write in Spell File Word CountEPSS 0.1%