Fallos del tipo CWE-787

5155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-46323CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46319CRITICALFingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bouEPSS 0.5%CVE-2022-46325CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46324CRITICALSome smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptioEPSS 0.5%CVE-2021-47719HIGHCNC_Ctrl DllUnregisterServer f5501 Access ViolationEPSS 0.5%CVE-2023-51569HIGHKofax Power PDF BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-21927CRITICALnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()EPSS 0.5%CVE-2026-29774MEDIUMFreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRectsEPSS 0.5%CVE-2021-47705HIGHCNC_Ctrl DllUnregisterServer Access ViolationEPSS 0.5%CVE-2020-21723—A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remoteEPSS 0.5%CVE-2026-10879CRITICALDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersEPSS 0.5%CVE-2026-49840CRITICALFreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingEPSS 0.5%CVE-2026-5187LOWHeap Out-of-Bounds Write in DecodeObjectId() in wolfSSLEPSS 0.5%CVE-2024-41879HIGHRE: New Edge T5 MSRC Case [DCMSFT-1294]EPSS 0.5%CVE-2025-29031CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.EPSS 0.5%CVE-2025-29030CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.EPSS 0.5%CVE-2025-41766HIGHStack buffer overflow on parsing web requestEPSS 0.5%CVE-2025-29029CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.EPSS 0.5%CVE-2025-25372HIGHNASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management ModuleEPSS 0.5%CVE-2026-2807CRITICALMemory safety bugs fixed in Firefox 148 and Thunderbird 148EPSS 0.5%