Fallos del tipo CWE-787

5154 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-50161CRITICALlibre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflowEPSS 0.5%CVE-2025-30276MEDIUMQsync CentralEPSS 0.5%CVE-2024-43688HIGHcron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE:EPSS 0.5%CVE-2026-8526HIGHOut of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox EPSS 0.5%CVE-2026-8524HIGHOut of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandboEPSS 0.5%CVE-2023-45681HIGHOut of bounds heap buffer write in stb_vorbisEPSS 0.5%CVE-2026-7951HIGHOut of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox vEPSS 0.5%CVE-2025-25898HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. This vEPSS 0.5%CVE-2023-45676HIGHMulti-byte write heap buffer overflow in start_decoder in stb_vorbisEPSS 0.5%CVE-2025-25897HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vuEPSS 0.5%CVE-2025-25901HIGHA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/EPSS 0.5%CVE-2026-41157CRITICALGPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3DEPSS 0.5%CVE-2026-70457HIGHrsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()EPSS 0.5%CVE-2023-29551HIGHMemory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2023-23606HIGHMemory safety bugs fixed in Firefox 109EPSS 0.5%CVE-2022-28288HIGHMozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present iEPSS 0.5%CVE-2024-6818HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6820HIGHIrfanView AWD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-0511HIGHMozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla FuzzEPSS 0.5%CVE-2022-22752HIGHMozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence EPSS 0.5%