Fallos del tipo CWE-787

5182 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-23504HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, iOS 15EPSS 0.4%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2023-28478HIGHTP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.EPSS 0.3%CVE-2024-30282HIGHAdobe Animate 2024 Out of Bound Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-26519HIGHmusl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusEPSS 0.3%CVE-2025-55036HIGHBIG-IP SSL Orchestrator vulnerabilityEPSS 0.3%CVE-2022-45202HIGHGPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.cEPSS 0.3%CVE-2025-54479HIGHBIG-IP PEM vulnerabilityEPSS 0.3%CVE-2025-58096HIGHBIG-IP TMM vulnerabilityEPSS 0.3%CVE-2024-9259HIGHIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9260HIGHIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-47661HIGHGPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_byteEPSS 0.3%CVE-2026-1484MEDIUMGlib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode()EPSS 0.3%CVE-2024-10573MEDIUMMpg123: buffer overflow when writing decoded pcm samplesEPSS 0.3%CVE-2026-20418CRITICALIn Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no EPSS 0.3%CVE-2023-44432HIGHKofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-16419CRITICALOut of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform aEPSS 0.3%CVE-2026-9967CRITICALOut of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a EPSS 0.3%CVE-2022-34251HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-14392CRITICALOut of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a EPSS 0.3%