Fallos del tipo CWE-787

5182 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-70354HIGH.NET Core Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-33636HIGHLIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64EPSS 0.4%CVE-2024-49551HIGHMedia Encoder | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2026-24797MEDIUMAn out of bounds write due to a missing bounds check in neka-nat/cupochEPSS 0.4%CVE-2023-26923HIGHMusescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additionEPSS 0.4%CVE-2026-5589MEDIUMOut-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.EPSS 0.4%CVE-2024-49553HIGHMedia Encoder | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2023-48630HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability IEPSS 0.4%CVE-2026-18269MEDIUMKenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution VulnerabilityEPSS 0.4%CVE-2024-22913HIGHA heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code executiEPSS 0.4%CVE-2023-50671HIGHIn exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected addEPSS 0.4%CVE-2022-42380HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-39386HIGHZDI-CAN-24057: Adobe Bridge AVI FIle Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-8669MEDIUMImager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF filesEPSS 0.4%CVE-2022-33265HIGHInformation exposure in Powerline Communication FirmwareEPSS 0.4%CVE-2022-42381HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-25423HIGHAn issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.EPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2022-42410HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-42382HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%