Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-49544HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-42926HIGHMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliEPSS 0.3%CVE-2026-40919MEDIUMGimp: gimp: denial of service via specially crafted seattle filmworks fileEPSS 0.3%CVE-2024-52994HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-81738LOWOpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEPSS 0.3%CVE-2023-37766—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/lEPSS 0.3%CVE-2022-41304HIGHAn Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK 2020 version and prior may lead to code execution through maliciously crafted FBX fEPSS 0.3%CVE-2023-37765—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpEPSS 0.3%CVE-2025-20633HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) cEPSS 0.3%CVE-2025-52513HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds EPSS 0.3%CVE-2024-49538HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-31910HIGHJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at /jerrEPSS 0.3%CVE-2026-4450HIGHOut of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.3%CVE-2026-84588MEDIUMA memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciouslyEPSS 0.3%CVE-2026-4440HIGHOut of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2026-4459HIGHOut of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corrEPSS 0.3%CVE-2024-11579HIGHLuxion KeyShot OBJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-48639HIGHAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IEPSS 0.3%CVE-2023-48625HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VIEPSS 0.3%CVE-2023-48626HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VEPSS 0.3%