Weaknesses of type CWE-787

5,145 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-24820HIGHRIOT-OS vulnerable to Integer Underflow during IPHC receiveEPSS 0.9%CVE-2023-24821HIGHRIOT-OS vulnerable to Integer Underflow during defragmentationEPSS 0.9%CVE-2022-40102HIGHTenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDset function. This vulnerability allows attackers to EPSS 0.9%CVE-2026-33816CRITICALCVE-2026-33816 in github.com/jackc/pgxEPSS 0.9%CVE-2026-33815CRITICALCVE-2026-33815 in github.com/jackc/pgxEPSS 0.9%CVE-2022-40104HIGHTenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDget function. This vulnerability allows attackers to EPSS 0.9%CVE-2023-33671CRITICALTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.EPSS 0.9%CVE-2022-3446HIGHHeap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.9%CVE-2021-34569CRITICALWAGO I/O-Check Service prone to Out-of-bounds WriteEPSS 0.9%CVE-2021-22751—A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of iEPSS 0.9%CVE-2026-61674CRITICALFluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handlerEPSS 0.9%CVE-2022-44156HIGHTenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.EPSS 0.9%CVE-2022-3725MEDIUMCrash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture fileEPSS 0.9%CVE-2022-44169HIGHTenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.EPSS 0.9%CVE-2022-44167HIGHTenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.EPSS 0.9%CVE-2022-44163HIGHTenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.EPSS 0.9%CVE-2022-44168HIGHTenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..EPSS 0.9%CVE-2022-44158HIGHTenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.EPSS 0.9%CVE-2026-7829HIGHUltraVNC repeater authenticated out-of-bounds write in rule parser via oversized tokenEPSS 0.9%CVE-2022-1041HIGHOut-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioningEPSS 0.9%