Fallos del tipo CWE-787

5154 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-78011HIGHFireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS)EPSS 0.5%CVE-2022-23561HIGHOut of bounds write in TFLiteEPSS 0.5%CVE-2026-2940MEDIUMZaher1307 tiny_web_server URL tiny.c out-of-bounds writeEPSS 0.5%CVE-2024-24956HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2018-16847HIGHAn OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvEPSS 0.5%CVE-2024-24958HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2026-78010HIGHFireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of ServiceEPSS 0.5%CVE-2024-24954HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2024-24959HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2025-20681CRITICALIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.5%CVE-2025-42877HIGHMemory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content ServerEPSS 0.5%CVE-2026-70456HIGHrsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()EPSS 0.5%CVE-2026-20657MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOEPSS 0.5%CVE-2026-8092HIGHMemory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2EPSS 0.5%CVE-2026-70458HIGHrsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED HandlingEPSS 0.5%CVE-2025-20684CRITICALIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.5%CVE-2026-82071HIGHInsufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteEPSS 0.5%CVE-2022-41168—Due to lack of proper memory management, when a victim opens a manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from unEPSS 0.5%CVE-2022-41177—Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file EPSS 0.5%CVE-2022-41172—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrustedEPSS 0.5%