Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2020-15214HIGHOut of bounds write in tensorflow-liteEPSS 0.7%CVE-2024-32608CRITICALHDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial ofEPSS 0.7%CVE-2024-20066HIGHIn modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no addiEPSS 0.7%CVE-2024-41131HIGHOut-of-bounds Write in SixLabors ImageSharpEPSS 0.7%CVE-2023-25746HIGHMemory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effEPSS 0.7%CVE-2023-0930HIGHHeap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.7%CVE-2016-20049CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer Overflow Remote Code ExecutionEPSS 0.7%CVE-2017-20227CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer OverflowEPSS 0.7%CVE-2023-25745HIGHMemory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.7%CVE-2024-35797HIGHmm: cachestat: fix two shmem bugsEPSS 0.7%CVE-2023-26551MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a clieEPSS 0.7%CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS 0.7%CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS 0.7%CVE-2025-41679MEDIUMUnauthenticated Buffer Overflow in Conftool Service Leading to Denial of ServiceEPSS 0.7%CVE-2026-23876HIGHHeap buffer overflow with attacker-controlled data in XBM parserEPSS 0.7%CVE-2024-35273HIGHA out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escEPSS 0.7%CVE-2025-49709CRITICALMemory corruption in canvas surfacesEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2022-36320CRITICALMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2022-41193—Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusEPSS 0.7%