Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-35088MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swfEPSS 0.3%CVE-2022-35087MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.EPSS 0.3%CVE-2022-44874MEDIUMwasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component op_CallIndirect at /mEPSS 0.3%CVE-2022-35086MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.EPSS 0.3%CVE-2024-30274HIGHAdobe Substance 3D Painter ABC File Parsing An Out-Of-Bounds Write VulnerabilityEPSS 0.3%CVE-2024-34124HIGHZDI-CAN-24031: Adobe Dimension SKP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-38932HIGHreadelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.EPSS 0.3%CVE-2023-30086MEDIUMBuffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcEPSS 0.3%CVE-2026-0113CRITICALIn ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remotEPSS 0.3%CVE-2026-12298MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2025-33133MEDIUMFixes to common vulnerabilities found in IBM Db2 High Performance UnloadEPSS 0.3%CVE-2026-0116CRITICALIn __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to reEPSS 0.3%CVE-2026-0114CRITICALIn Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additioEPSS 0.3%CVE-2026-0111CRITICALIn ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remotEPSS 0.3%CVE-2026-0120CRITICALIn modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additioEPSS 0.3%CVE-2025-20704HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.3%CVE-2022-42901HIGHBentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMTEPSS 0.3%CVE-2024-31980HIGHA vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.256), Parasolid V36.0 (All versions < V36.0.210), Parasolid V36EPSS 0.3%CVE-2026-24827HIGHOut-of-bounds write in Commander-GeniusEPSS 0.3%CVE-2026-14400HIGHOut of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%