Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-12520MEDIUMStack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlersEPSS 0.3%CVE-2026-1284HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.3%CVE-2023-34325HIGHMultiple vulnerabilities in libfsimage disk handlingEPSS 0.3%CVE-2022-32944HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOEPSS 0.3%CVE-2023-45734MEDIUMDsoftbus has an out-of-bounds write vulnerabilityEPSS 0.3%CVE-2022-42947HIGHA maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerEPSS 0.3%CVE-2026-55737MEDIUMHeap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoderEPSS 0.3%CVE-2026-67549HIGHOpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds writeEPSS 0.3%CVE-2026-21897HIGHCryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_ParametersEPSS 0.3%CVE-2022-1943—A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation wEPSS 0.3%CVE-2025-9456HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2022-43045MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manEPSS 0.3%CVE-2018-25230MEDIUMFree IP Switcher 3.1 Denial of Service via Computer NameEPSS 0.3%CVE-2026-10999MEDIUMInteger overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2025-9452HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2022-32820HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11EPSS 0.3%CVE-2026-1837HIGHlibjxl: Out-of-bounds write in grayscale color transformation when using LCMS2EPSS 0.3%CVE-2024-30307HIGHAdobe Substance 3D Painter BMP File Parsing Out Of Bounds Write VulnerabilityEPSS 0.3%CVE-2026-48040MEDIUMnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessEPSS 0.3%CVE-2024-20057HIGHIn keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.3%