Fallos del tipo CWE-787

5208 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2024-9733HIGHTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-43588HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-17252HIGHUnauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management InterfaceEPSS 0.3%CVE-2026-94054HIGHExim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.EPSS 0.3%CVE-2025-43505HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously craftEPSS 0.3%CVE-2025-2020HIGHAshlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-54509HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, mEPSS 0.3%CVE-2025-21121HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-21489HIGHHeap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.EPSS 0.3%CVE-2022-32860HIGHAn out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, mEPSS 0.3%CVE-2025-43581HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-72897HIGHOut-of-Bounds Access After SSL_set_SSL_CTX() During a HandshakeEPSS 0.3%CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS 0.3%CVE-2025-71004MEDIUMA segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2022-48423HIGHIn the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.EPSS 0.3%CVE-2026-8314HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%CVE-2026-8312HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%CVE-2021-0153HIGHOut-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of priviEPSS 0.3%CVE-2026-8085HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%