Fallos del tipo CWE-787

5205 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-0970HIGHSerial API Buffer Overflow in Z/IP GatewayEPSS 0.3%CVE-2025-26784MEDIUMAn issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2026-53196MEDIUMUSB: serial: io_ti: fix heap overflow in get_manuf_info()EPSS 0.3%CVE-2024-4080HIGHMemory Corruption Due to Improper Length Checks in LabVIEW tdcore.dllEPSS 0.3%CVE-2025-36937CRITICALIn AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This coEPSS 0.3%CVE-2025-6651HIGHPDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-50262HIGHbpf: Fix out-of-bounds write in trie_get_next_key()EPSS 0.3%CVE-2023-37644MEDIUMSWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. ThiEPSS 0.3%CVE-2024-9744HIGHTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-1330HIGHIBM CICS TX code executionEPSS 0.3%CVE-2025-1329HIGHIBM CICS TX code executionEPSS 0.3%CVE-2024-9736HIGHTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-6654HIGHPDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-6659HIGHPDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-6647HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-64301HIGHAn out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker cEPSS 0.3%CVE-2026-56114MEDIUMdhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()EPSS 0.3%CVE-2024-9740HIGHTungsten Automation Power PDF BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9746HIGHTungsten Automation Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%