Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-0297MEDIUMGlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel HandshakeEPSS 0.3%CVE-2023-31982HIGHSngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c.EPSS 0.3%CVE-2024-33764MEDIUMlunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.EPSS 0.3%CVE-2018-9466HIGHIn the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of priviEPSS 0.3%CVE-2025-20711HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2025-3873MEDIUMBuffer overflow in Si91x crypto APIsEPSS 0.3%CVE-2023-48628HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability IIIEPSS 0.3%CVE-2023-26330HIGHZDI-CAN-20146: Adobe Dimension USD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-35086MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.EPSS 0.3%CVE-2023-31981HIGHSngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.EPSS 0.3%CVE-2024-0646HIGHKernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destinationEPSS 0.3%CVE-2022-2892HIGHMeasuresoft ScadaPro Server Out-of-bounds WriteEPSS 0.3%CVE-2022-35088MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swfEPSS 0.3%CVE-2023-48627HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability IVEPSS 0.3%CVE-2022-44874MEDIUMwasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component op_CallIndirect at /mEPSS 0.3%CVE-2023-48629HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability IIEPSS 0.3%CVE-2022-35087MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.EPSS 0.3%CVE-2022-2866HIGHFATEK Automation FvDesigner Out-of-bounds WriteEPSS 0.3%CVE-2024-30274HIGHAdobe Substance 3D Painter ABC File Parsing An Out-Of-Bounds Write VulnerabilityEPSS 0.3%CVE-2022-38932HIGHreadelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.EPSS 0.3%