Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-2044HIGHMOXA NPort 5110 Out-of-bounds WriteEPSS 0.7%CVE-2026-42484CRITICALA heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or EPSS 0.7%CVE-2026-85452HIGHMOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS IdentifiersEPSS 0.7%CVE-2024-1913HIGH An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execEPSS 0.7%CVE-2023-51084CRITICALhyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.EPSS 0.7%CVE-2019-25654HIGHCore FTP/SFTP Server 1.2 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2025-12195HIGHWatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec ConfigurationEPSS 0.7%CVE-2023-5406MEDIUMServer communication with a controller can lead to remote code execution using a specially crafted message from the controller. See HoneywelEPSS 0.7%CVE-2026-48773CRITICALProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handlingEPSS 0.7%CVE-2019-25600HIGHUltraVNC Viewer 1.2.2.4 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2026-22858MEDIUMFreeRDP has a global-buffer-overflow in crypto_base64_decodeEPSS 0.7%CVE-2024-44375HIGHD-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.EPSS 0.7%CVE-2026-4699HIGHIncorrect boundary conditions in the Layout: Text and Fonts componentEPSS 0.7%CVE-2026-4685HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.7%CVE-2025-5099CRITICALKL-001-2025-004: Mobile Dynamix PrinterShare Mobile Print Out-of-bounds WriteEPSS 0.7%CVE-2026-4697HIGHIncorrect boundary conditions in the Audio/Video: Web Codecs componentEPSS 0.7%CVE-2022-44752CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2022-44754CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView.EPSS 0.7%CVE-2022-44753CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2022-44751CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%