Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2026-54789HIGHmod_auth_openidc has out-of-bounds read and write in state cookie parsingEPSS 0.7%CVE-2023-45985HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the functioEPSS 0.7%CVE-2026-44421HIGHFreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypassEPSS 0.7%CVE-2026-43790CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A EPSS 0.7%CVE-2024-7535HIGHInappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption EPSS 0.7%CVE-2024-25448HIGHAn issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafteEPSS 0.7%CVE-2026-37457HIGHAn off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stablEPSS 0.7%CVE-2025-0690MEDIUMGrub2: read: integer overflow may lead to out-of-bounds writeEPSS 0.7%CVE-2023-6931HIGHOut-of-bounds write in Linux kernel's Performance Events system componentEPSS 0.7%CVE-2021-47772HIGH10-Strike Network Inventory Explorer Pro 9.31 - Buffer Overflow (SEH)EPSS 0.7%CVE-2023-31488CRITICALHyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, CiscoEPSS 0.7%CVE-2023-33552HIGHHeap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code viaEPSS 0.7%CVE-2022-37937CRITICALPre-auth memory corruption in HPE ServiceguardEPSS 0.7%CVE-2022-34485CRITICALMozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of thesEPSS 0.7%CVE-2022-42932HIGHMozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some oEPSS 0.7%CVE-2022-4608HIGHA vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can onlyEPSS 0.7%CVE-2026-56786CRITICALRTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 MessageEPSS 0.7%CVE-2024-25200HIGHEspruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.EPSS 0.7%CVE-2023-26064CRITICALCertain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.EPSS 0.7%CVE-2020-27005—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%