Fallos del tipo CWE-787

5156 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-34589HIGHOpenEXR: DWA Lossy Decoder Heap Out-of-Bounds WriteEPSS 0.5%CVE-2026-17264MEDIUMMedixant RadiAnt DICOM Out-of-bounds writeEPSS 0.5%CVE-2024-23120HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2026-45770HIGHSuricata lua: excessive flow variable registration can bypass sandboxEPSS 0.5%CVE-2024-45539HIGHOut-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology EPSS 0.5%CVE-2026-34195HIGHGPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexesEPSS 0.5%CVE-2026-43815HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.5%CVE-2026-84444HIGHlibheif uncompressed tiled image encoding allows out-of-bounds writeEPSS 0.5%CVE-2025-2750MEDIUMOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds writeEPSS 0.5%CVE-2023-39485HIGHPDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-17272HIGHIBM i is Affected By a Denial of Service in HTTP Server []EPSS 0.5%CVE-2026-28972MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 andEPSS 0.5%CVE-2026-86882MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.5%CVE-2026-57021MEDIUMJunos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crashEPSS 0.5%CVE-2026-68579HIGHFreeRDP before 3.30.0 Heap Overflow via CliprdrStream_ReadEPSS 0.5%CVE-2022-41902HIGHOut of bounds write in grappler in TensorflowEPSS 0.5%CVE-2021-3696—A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap EPSS 0.5%CVE-2025-0143MEDIUMZoom Workplace Apps for Linux - Out-of-bounds WriteEPSS 0.5%CVE-2026-13087HIGHKernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...EPSS 0.5%CVE-2024-23969HIGHChargePoint Home Flex wlanchnllst Out-Of-Bounds WriteEPSS 0.5%