Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2021-32995—Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-EPSS 1.0%CVE-2023-40018HIGHFreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component IDEPSS 1.0%CVE-2022-42167CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.EPSS 1.0%CVE-2022-42163CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.EPSS 1.0%CVE-2022-42171CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.EPSS 1.0%CVE-2022-42168CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.EPSS 1.0%CVE-2022-42169CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.EPSS 1.0%CVE-2022-42170CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.EPSS 1.0%CVE-2022-42164CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.EPSS 1.0%CVE-2022-42165CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.EPSS 1.0%CVE-2022-42166CRITICALTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.EPSS 1.0%CVE-2025-14237CRITICALBuffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on theEPSS 1.0%CVE-2022-42227HIGHjsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.EPSS 1.0%CVE-2022-20607HIGHIn the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executEPSS 1.0%CVE-2022-22738HIGHApplying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially EPSS 1.0%CVE-2024-22916CRITICALIn D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.EPSS 1.0%CVE-2021-33684MEDIUMSAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUCEPSS 1.0%CVE-2023-24819CRITICALRIOT-OS vulnerable to Buffer Overflow during IPHC receiveEPSS 1.0%CVE-2023-24823CRITICALRIOT-OS vulnerable to Packet Type Confusion during IPHC sendEPSS 1.0%CVE-2022-26719HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS EPSS 1.0%