Weaknesses of type CWE-787

5,231 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-57035MEDIUMIn multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privileEPSS 0.1%CVE-2026-55365MEDIUMIn multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalatEPSS 0.1%CVE-2023-21046MEDIUMIn ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2023-20931HIGHIn avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to locaEPSS 0.1%CVE-2024-22005HIGHthere is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additionalEPSS 0.1%CVE-2022-32634MEDIUMIn ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2025-48540HIGHIn processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead EPSS 0.1%CVE-2023-32811MEDIUMIn connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalationEPSS 0.1%CVE-2023-32806MEDIUMIn wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege wEPSS 0.1%CVE-2022-32625MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2022-32626MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2025-48624HIGHIn multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local eEPSS 0.1%CVE-2026-0119MEDIUMIn usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physicEPSS 0.1%CVE-2023-20700MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-20701MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-20837MEDIUMIn seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2023-21050MEDIUMIn load_png_image of ExynosHWCHelper.cpp, there is a possible out of bounds write due to improper input validation. This could lead to localEPSS 0.1%CVE-2022-48239MEDIUMIn camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-48374MEDIUMIn tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysteEPSS 0.1%CVE-2022-47470MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with SystemEPSS 0.1%