Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-11928CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2023-21597HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-44245HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, mEPSS 0.3%CVE-2023-30414MEDIUMJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.EPSS 0.3%CVE-2022-44513HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-39394HIGHAdobe Indesign 2024 PDF File Parsing Out Of Bound Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21595HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-32866HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS MontereEPSS 0.3%CVE-2026-13873MEDIUMOut of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2021-39822HIGHAdobe InDesign BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-57807LOWImageMagick BlobStream Forward-Seek Under-AllocationEPSS 0.3%CVE-2022-31610HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabiEPSS 0.3%CVE-2025-1276HIGHDWG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2026-6325LOWOut-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listEPSS 0.3%CVE-2026-20432HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.3%CVE-2022-3219LOWGnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressEPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%CVE-2023-34823MEDIUMfdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.EPSS 0.3%CVE-2025-27374MEDIUMAn issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 10EPSS 0.3%CVE-2026-24817HIGHA potential heap-buffer overflow in praydog/UEVREPSS 0.3%