Weaknesses of type CWE-787

5,145 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2023-24094HIGHAn issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.EPSS 0.8%CVE-2022-45766CRITICALHardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remotEPSS 0.8%CVE-2022-43027CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewaEPSS 0.8%CVE-2022-43025CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServeEPSS 0.8%CVE-2022-43029CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.EPSS 0.8%CVE-2022-43026CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCEPSS 0.8%CVE-2022-43028CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCEPSS 0.8%CVE-2022-43024CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServeEPSS 0.8%CVE-2022-27653—A vulnerability has been identified in Simcenter Femap (All versions < V2022.2). The affected application contains an out of bounds write paEPSS 0.8%CVE-2026-73514HIGHPostGIS address_standardizer Out-of-Bounds Write via standardize_address()EPSS 0.8%CVE-2026-43810CRITICALThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOEPSS 0.8%CVE-2026-43803CRITICALAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.8%CVE-2023-7244CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2026-78524HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-7243CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2023-0847MEDIUM The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write prior to implementatEPSS 0.8%CVE-2026-33721MEDIUMMapServer has heap buffer overflow in SLD `Categorize` Threshold parsingEPSS 0.8%CVE-2024-2184CRITICALBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may alloEPSS 0.8%CVE-2023-33551HIGHHeap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary cEPSS 0.8%CVE-2023-34940HIGHAsus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerabiliEPSS 0.8%