Fallos del tipo CWE-787

5154 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-41177—Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file EPSS 0.5%CVE-2022-41167—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrustedEPSS 0.5%CVE-2022-41172—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrustedEPSS 0.5%CVE-2022-41170—Due to lack of proper memory management, when a victim opens a manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrEPSS 0.5%CVE-2022-41179—Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from unEPSS 0.5%CVE-2026-78161MEDIUMwarmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds writeEPSS 0.5%CVE-2023-21054HIGHIn EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lEPSS 0.5%CVE-2024-33008MEDIUMMemory Corruption vulnerability in SAP Replication ServerEPSS 0.5%CVE-2022-28668HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.9.2. User interaEPSS 0.5%CVE-2022-37234HIGHNetgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary iEPSS 0.5%CVE-2020-1751MEDIUMAn out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtraceEPSS 0.5%CVE-2024-5844HIGHHeap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read EPSS 0.5%CVE-2026-58154CRITICALApache Traffic Server: Memory-safety errors in MIME and header parsingEPSS 0.5%CVE-2022-39805—Due to lack of proper memory management, when a victim opens a manipulated Computer Graphics Metafile (.cgm, CgmTranslator.exe) file receiveEPSS 0.5%CVE-2024-56406HIGHPerl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytesEPSS 0.5%CVE-2026-62817HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-51597HIGHKofax Power PDF U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-6786HIGHMemory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2026-55827HIGHFreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decodeEPSS 0.5%CVE-2026-6785HIGHMemory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%