Fallos del tipo CWE-787

5204 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-45152HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-50230HIGHnilfs2: fix kernel bug due to missing clearing of checked flagEPSS 0.3%CVE-2026-75892MEDIUMOut of bounds write in PDP ctx GSN-Address decodeEPSS 0.3%CVE-2024-41864HIGHAdobe Substance 3D Designer ICO Parsing Out-Of-Bounds Write VulnerabilityEPSS 0.3%CVE-2026-35226HIGHOut-of-bounds Write in CODESYS PROFINET ControllerEPSS 0.3%CVE-2024-45144HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-30290HIGHAdobe FrameMaker WEBP File Parsing Out Of Bound WriteEPSS 0.3%CVE-2020-36602MEDIUMThere is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and EPSS 0.3%CVE-2026-16886MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2026-25506HIGHMUNGE has a buffer overflow in message unpacking allows key leakage and credential forgeryEPSS 0.3%CVE-2026-11173HIGHOut of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execEPSS 0.3%CVE-2025-24139HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS VeEPSS 0.3%CVE-2025-24014MEDIUMsegmentation fault in win_line() in Vim < 9.1.1043EPSS 0.3%CVE-2022-43044MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isoEPSS 0.3%CVE-2025-49492HIGHOut-of-bounds write in lte-telephonyEPSS 0.3%CVE-2025-12603LOW/etc/timezone can be Arbitrarily WrittenEPSS 0.3%CVE-2025-12602LOW/etc/avahi/services/z9.service can be Arbitrarily WrittenEPSS 0.3%CVE-2025-10884HIGHCATPART File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2023-32538HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%CVE-2023-32273HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%