Fallos del tipo CWE-787

5180 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2021-46879HIGHAn issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in EPSS 0.4%CVE-2023-52386HIGHOut-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-35222MEDIUMHiCOS Citizen verification component - Stack Buffer OverflowEPSS 0.4%CVE-2026-34380MEDIUMOpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompressionEPSS 0.4%CVE-2023-52110HIGHThe sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2026-41907HIGHuuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is providedEPSS 0.4%CVE-2021-45464HIGHkvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute EPSS 0.4%CVE-2023-22614HIGHAn issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS GuaEPSS 0.4%CVE-2022-35895HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input paramEPSS 0.4%CVE-2022-46693HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS EPSS 0.4%CVE-2024-44552MEDIUMTenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.EPSS 0.4%CVE-2021-3501—A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, whicEPSS 0.4%CVE-2026-15105MEDIUMdavenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds writeEPSS 0.4%CVE-2023-26965MEDIUMloadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.EPSS 0.4%CVE-2026-17476MEDIUMIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2023-53372HIGHsctp: fix a potential overflow in sctp_ifwdtsn_skipEPSS 0.4%CVE-2026-1678CRITICALdns: memory‑safety issue in the DNS name parserEPSS 0.4%CVE-2024-49823MEDIUMIBM Common Cryptographic Architecture denial of serviceEPSS 0.4%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.4%CVE-2026-6681LOWPKCS#7 decode ignores caller output buffer size, writing past buffer boundsEPSS 0.4%