Fallos del tipo CWE-787

5158 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-62818CRITICALAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.5%CVE-2026-79188CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-79131CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandboxEPSS 0.5%CVE-2026-79138CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-5733HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.5%CVE-2026-79189CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-85050CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46274HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.EPSS 0.5%CVE-2026-87621CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-79043CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-79019CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2024-46264HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.EPSS 0.5%CVE-2026-87438CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46267HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.EPSS 0.5%CVE-2024-46263HIGHcute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.EPSS 0.5%CVE-2026-87638CRITICALOut of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2024-46276HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.EPSS 0.5%CVE-2024-46259HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.EPSS 0.5%CVE-2023-38072HIGHA vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), TeamcenEPSS 0.5%CVE-2026-5735HIGHMemory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.5%