Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-53855HIGHAn out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadeEPSS 0.3%CVE-2025-15359CRITICALDVP-12SE11T - Out-of-bound memory write VulnerabilityEPSS 0.3%CVE-2022-43039MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at EPSS 0.3%CVE-2023-40152HIGHFuji Electric Tellus Lite V-Simulator Out-of-bounds WriteEPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2022-35090MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.EPSS 0.3%CVE-2024-43760HIGHPhotoshop Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-44312MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called froEPSS 0.3%CVE-2024-53842CRITICALIn cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead toEPSS 0.3%CVE-2024-20103CRITICALIn wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with noEPSS 0.3%CVE-2026-42910HIGHWindows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-22911HIGHA stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.EPSS 0.3%CVE-2023-27754MEDIUMvox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attackeEPSS 0.3%CVE-2024-22955HIGHswftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576EPSS 0.3%CVE-2026-71345HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-20100CRITICALIn wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no aEPSS 0.3%CVE-2023-37174—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedumEPSS 0.3%CVE-2022-47518HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wiEPSS 0.3%CVE-2024-37022HIGHFuji Electric Tellus Lite V-Simulator Out-of-bounds WriteEPSS 0.3%CVE-2024-52994HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%