Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-40653HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2022-40654HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2024-44284MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, mEPSS 0.6%CVE-2023-51742MEDIUMBuffer Overflow vulnerability in Skyworth RouterEPSS 0.6%CVE-2026-31402CRITICALnfsd: fix heap overflow in NFSv4.0 LOCK replay cacheEPSS 0.6%CVE-2022-40652HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.6%CVE-2023-32158HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-1017CRITICALMemory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7EPSS 0.6%CVE-2024-5695CRITICALIf an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been tEPSS 0.6%CVE-2024-6817HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-5701CRITICALMemory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2024-6815HIGHIrfanView RLE File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-39927HIGHOut-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected EPSS 0.6%CVE-2026-16907HIGHIBM i is Affected By Multiple Vulnerabilities in the Debug ServerEPSS 0.6%CVE-2024-30374HIGHLuxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-41184—Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted EPSS 0.6%CVE-2022-1841HIGHOut-of-bound write in tcp_flagsEPSS 0.6%CVE-2026-62648HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated EPSS 0.6%CVE-2025-0910HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%