Fallos del tipo CWE-787

5208 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-8085HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%CVE-2025-27166HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-28064LOW Dell BIOS contains an Out-of-bounds Write vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, lEPSS 0.3%CVE-2025-27175HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2019-25601MEDIUMUltraVNC Launcher 1.2.2.4 Denial of Service Buffer OverflowEPSS 0.3%CVE-2024-11793HIGHFuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-38533MEDIUMZKsync Era invalid stack addressing conversionEPSS 0.3%CVE-2021-33060HIGHOut-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of prEPSS 0.3%CVE-2024-11794HIGHFuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11796HIGHFuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11801HIGHFuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-44215MEDIUMNanaZip: Heap out-of-bounds write in NanaZip UFS directory parserEPSS 0.3%CVE-2025-27178HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-11798HIGHFuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11803HIGHFuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-11797HIGHFuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-48864HIGHLibsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page dataEPSS 0.3%CVE-2025-53524HIGHFuji Electric Monitouch V-SFT-6 Out-of-bounds WriteEPSS 0.3%CVE-2024-41859HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2019-25634HIGHBase64 Decoder 1.1.2 Local Buffer Overflow SEH EgghunterEPSS 0.3%