Fallos del tipo CWE-787

5155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-38638LOWQTS, QuTS heroEPSS 0.5%CVE-2024-43091CRITICALIn filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code EPSS 0.5%CVE-2019-25478HIGHGetGo Download Manager 6.2.2.3300 Buffer Overflow DoSEPSS 0.5%CVE-2026-59087HIGHGimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocationEPSS 0.5%CVE-2023-27909HIGHAn Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX EPSS 0.5%CVE-2023-3090HIGHOut-of-bounds write in Linux kernel's ipvlan network driverEPSS 0.5%CVE-2024-5513HIGHKofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-32827MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able EPSS 0.5%CVE-2026-34987CRITICALWasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessEPSS 0.5%CVE-2024-24957HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2023-20954CRITICALIn SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code eEPSS 0.5%CVE-2024-24955HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2023-20951CRITICALIn gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remoEPSS 0.5%CVE-2023-21057CRITICALIn ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to EPSS 0.5%CVE-2025-60338HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerabiliEPSS 0.5%CVE-2026-26459HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when prEPSS 0.5%CVE-2026-55233HIGHOpenResty: Buffer overflow when writing PROXY protocol v2 header to upstreamEPSS 0.5%CVE-2023-2124—An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with EPSS 0.5%CVE-2022-46326CRITICALSome smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptioEPSS 0.5%CVE-2026-66041HIGHFFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc FilterEPSS 0.5%