Fallos del tipo CWE-787

5204 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-0686MEDIUMGrub2: romfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading datEPSS 0.3%CVE-2026-11037CRITICALOut of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.3%CVE-2026-62653HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol thEPSS 0.3%CVE-2025-10882HIGHX_T File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-0685MEDIUMGrub2: jfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading dataEPSS 0.3%CVE-2023-32201HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may leEPSS 0.3%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.3%CVE-2022-47086MEDIUMGPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.cEPSS 0.3%CVE-2023-31284HIGHillumos illumos-gate before 676abcb has a stack buffer overflow in /dev/net, leading to privilege escalation via a stat on a long file name EPSS 0.3%CVE-2026-0126HIGHIn WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additioEPSS 0.3%CVE-2024-23270HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma EPSS 0.3%CVE-2026-0159HIGHIn Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no aEPSS 0.3%CVE-2026-0170HIGHIn Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote EPSS 0.3%CVE-2026-0148HIGHIn multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could leadEPSS 0.3%CVE-2023-4754MEDIUMOut-of-bounds Write in gpac/gpacEPSS 0.3%CVE-2026-0147HIGHIn __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. ThiEPSS 0.3%CVE-2026-0146HIGHIn mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This coulEPSS 0.3%CVE-2022-42946HIGHParsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in EPSS 0.3%CVE-2026-10114MEDIUMOpen5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds writeEPSS 0.3%CVE-2024-47963HIGHOut-of-bounds Write vulnerability in Delta Electronics CNCSoft-G2EPSS 0.3%