Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-22056HIGHnetfilter: nft_tunnel: fix geneve_opt type confusion additionEPSS 0.3%CVE-2023-47057HIGHZDI-CAN-21764: Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-31696HIGHVMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local acceEPSS 0.3%CVE-2023-26328HIGHZDI-CAN-20212: Adobe Dimension USD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-45587MEDIUMStack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.EPSS 0.3%CVE-2026-7354HIGHOut of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2022-41686MEDIUMOut-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The proc ...EPSS 0.3%CVE-2023-34305HIGHAshlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-47314HIGHOut-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5daEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2022-43040HIGHGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedEPSS 0.3%CVE-2024-24922HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2022-28667MEDIUMOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially eEPSS 0.3%CVE-2024-24924HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2024-24920HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2023-47046MEDIUMZDI-CAN-21684: Adobe Audition MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-23795HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2023-47063HIGHAdobe Illustrator 2023 CC 27.7 Memory Corruption Out-Of-Bounds-Write Vulnerability IV.EPSS 0.3%CVE-2023-31906HIGHJerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jEPSS 0.3%CVE-2022-45586MEDIUMStack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.EPSS 0.3%