Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-2922HIGHGStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-27194HIGHMedia Encoder | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2021-43018HIGHAdobe Photoshop JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-4090—An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1]EPSS 0.3%CVE-2022-44318MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpreEPSS 0.3%CVE-2024-12671HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-1847HIGHMultiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.3%CVE-2026-11604MEDIUMAn incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authentiEPSS 0.3%CVE-2022-46346HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.3%CVE-2026-49295HIGHlibde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPSEPSS 0.3%CVE-2023-48632HIGHZDI-CAN-22172: Adobe After Effects AEP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-46348HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.3%CVE-2022-47521HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/micEPSS 0.3%CVE-2024-6442MEDIUMBluetooth: ASCS Unchecked tailroom of the response bufferEPSS 0.3%CVE-2018-7517—In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability.EPSS 0.3%CVE-2022-43071MEDIUMA stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via EPSS 0.3%CVE-2025-1938MEDIUMMemory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8EPSS 0.3%CVE-2025-53855HIGHAn out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadeEPSS 0.3%CVE-2025-21161HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-41211HIGHDue to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise AuEPSS 0.3%