Fallos del tipo CWE-787

5202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-1837HIGHlibjxl: Out-of-bounds write in grayscale color transformation when using LCMS2EPSS 0.3%CVE-2024-46919MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to EPSS 0.3%CVE-2026-15390CRITICALOut-of-bounds write in Das U-BootEPSS 0.3%CVE-2024-22562HIGHswftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.EPSS 0.3%CVE-2026-0149HIGHIn RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution withEPSS 0.3%CVE-2026-41676HIGHrust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1EPSS 0.3%CVE-2024-27050HIGHlibbpf: Use OPTS_SET() macro in bpf_xdp_query()EPSS 0.3%CVE-2026-0200HIGHIn Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege EPSS 0.3%CVE-2024-45780MEDIUMGrub2: fs/tar: integer overflow causes heap oob writeEPSS 0.3%CVE-2022-32865HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrEPSS 0.3%CVE-2021-47781MEDIUMCmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)EPSS 0.3%CVE-2026-18289HIGHOriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-21157HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-18293HIGHOriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-43667HIGHStack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrEPSS 0.3%CVE-2025-24452HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-46835MEDIUMx86/AMD: mismatch in IOMMU quarantine page table levelsEPSS 0.3%CVE-2025-30464HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, maEPSS 0.3%CVE-2026-18290HIGHOriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-26513HIGHOut-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauthenticated user to poEPSS 0.3%