Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-26805CRITICALTenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.EPSS 0.9%CVE-2023-29696CRITICALH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.EPSS 0.9%CVE-2022-46723—This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be ableEPSS 0.9%CVE-2023-26806CRITICALTenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,EPSS 0.9%CVE-2022-48130CRITICALTenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNeEPSS 0.9%CVE-2021-28816HIGHStack Buffer Overflow Vulnerabilities in QTS, QuTS hero, and QuTScloudEPSS 0.9%CVE-2023-34566CRITICALTenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.EPSS 0.9%CVE-2022-1229HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. EPSS 0.9%CVE-2023-49404CRITICALTenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.EPSS 0.9%CVE-2023-49424HIGHTenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.EPSS 0.9%CVE-2022-26761HIGHA memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2022-004 Catalina, macOS Big SEPSS 0.9%CVE-2010-20115CRITICALVermillion FTP <= 1.31 Daemon PORT Command Memory CorruptionEPSS 0.9%CVE-2023-36272HIGHLibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.EPSS 0.9%CVE-2020-8109MEDIUMBitdefender ace.xmd parser out-of-bounds write (VA-8772)EPSS 0.9%CVE-2021-47785HIGHEther_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)EPSS 0.9%CVE-2026-5857CRITICALContiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP SegmentsEPSS 0.9%CVE-2022-3050HIGHHeap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage EPSS 0.9%CVE-2021-33647—When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside EPSS 0.9%CVE-2020-15211MEDIUMOut of bounds access in tensorflow-liteEPSS 0.9%CVE-2023-33672HIGHTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.EPSS 0.9%