Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2019-14821HIGHAn out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements tEPSS 0.8%CVE-2022-36054MEDIUMOut-of-bounds write when decompressing 6LoWPAN payload in Contiki-NGEPSS 0.8%CVE-2022-46709CRITICALA memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able EPSS 0.8%CVE-2023-34293HIGHAshlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-30949CRITICALAn issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.EPSS 0.8%CVE-2022-34759HIGHA CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTEPSS 0.8%CVE-2026-6100CRITICALUse-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressureEPSS 0.8%CVE-2022-4920CRITICALHeap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UEPSS 0.8%CVE-2022-37903HIGHA vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web intEPSS 0.8%CVE-2021-33681MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out ofEPSS 0.8%CVE-2023-45675MEDIUM0 byte write heap buffer overflow in start_decoder in stb_vorbisEPSS 0.8%CVE-2026-22853MEDIUMFreeRDP has a heap-buffer-overflow in ndr_read_uint8ArrayEPSS 0.8%CVE-2023-49552HIGHAn Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function inEPSS 0.8%CVE-2023-32397—A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOSEPSS 0.8%CVE-2023-50227HIGHParallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-30371CRITICALIn Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.EPSS 0.8%CVE-2023-30376CRITICALIn Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.EPSS 0.8%CVE-2023-30375CRITICALIn Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.EPSS 0.8%CVE-2023-30369CRITICALTenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.EPSS 0.8%CVE-2023-31568HIGHPodofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.EPSS 0.8%