Weaknesses of type CWE-787

5,146 results

Escrita fora dos limites da memória

Ocorre quando o código escreve dados em um endereço de memória fora do intervalo alocado para uma estrutura (array, buffer, objeto). O programa não valida o tamanho ou índice antes de escrever, permitindo sobrescrever memória adjacente — causando corrupção de dados, queda da aplicação ou execução arbitrária de código.

Example

Um formulário web que copia o valor de um campo do usuário para um buffer de 64 bytes sem verificar o comprimento: se o atacante enviar 200 caracteres, a escrita invade a memória vizinha e pode sobrescrever um ponteiro de função ou variável crítica.

How to mitigate

Sempre validar tamanhos de entrada antes de copiar (usar `strncpy` em vez de `strcpy`, ou bibliotecas seguras como `bounds-checking`); usar linguagens com verificação automática de limites (Java, Rust); aplicar testes de fuzzing e análise estática de código para detectar escritas desprotegidas.

CVE-2022-32810HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. AnEPSS 0.7%CVE-2026-12844HIGHList::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise functionEPSS 0.7%CVE-2024-36761CRITICALnaga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.EPSS 0.7%CVE-2026-59205HIGHPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatchEPSS 0.7%CVE-2026-8053HIGHFlatBSON Duplicate Field Index DriftEPSS 0.7%CVE-2026-59199HIGHPillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowEPSS 0.7%CVE-2022-23092HIGHMissing bounds check in 9p message handlingEPSS 0.7%CVE-2026-96891CRITICALD-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds writeEPSS 0.7%CVE-2022-43034MEDIUMAn issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) funEPSS 0.7%CVE-2022-43035MEDIUMAn issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to aEPSS 0.7%CVE-2022-28318HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. EPSS 0.7%CVE-2023-50711MEDIUM`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory accessEPSS 0.7%CVE-2023-25078CRITICALDoS due to heap overflowEPSS 0.7%CVE-2023-23585CRITICALServer DoS due to heap overflowEPSS 0.7%CVE-2024-23122HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.7%CVE-2024-23978CRITICALHeap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be exeEPSS 0.7%CVE-2024-21780HIGHStack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in aEPSS 0.7%CVE-2026-73193CRITICALDBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparseEPSS 0.6%CVE-2024-32669MEDIUMPossible stack overflow due to a string encoding processing errorEPSS 0.6%CVE-2025-30356CRITICALHeap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`EPSS 0.6%