Weaknesses of type CWE-787

5,228 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-32854MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2026-21085HIGHOut-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.EPSS 0.1%CVE-2024-20027HIGHIn da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2025-29933MEDIUMImproper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of EPSS 0.1%CVE-2026-4430MEDIUMHeap Buffer Overflow in AgileEngineEPSS 0.1%CVE-2024-45543MEDIUMOut-of-bounds Write in AudioEPSS 0.1%CVE-2026-102004HIGHVxWorks 7EPSS 0.1%CVE-2026-20714HIGHOut-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escaEPSS 0.1%CVE-2024-20145MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2024-20144MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2023-32882MEDIUMIn battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2024-20143MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2026-13467HIGHSystemic Missing Address Validation in SiP SMC HandlersEPSS 0.1%CVE-2026-17051MEDIUMOut-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell lengthEPSS 0.1%CVE-2025-20650MEDIUMIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2025-46585HIGHOut-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availabilEPSS 0.1%CVE-2026-20455HIGHIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2026-63273MEDIUMHeap buffer overflow in PDF import encryption handlingEPSS 0.1%CVE-2026-21110MEDIUMOut-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.EPSS 0.1%CVE-2026-0799HIGHOOBR and OOBW in libpcap before 1.10.7EPSS 0.1%