Fallos del tipo CWE-787

5209 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2018-25211HIGHAllok Video Splitter 3.1.1217 Buffer Overflow via License NameEPSS 0.3%CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2024-35976HIGHxsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RINGEPSS 0.3%CVE-2024-56615HIGHbpf: fix OOB devmap writes when deleting elementsEPSS 0.3%CVE-2024-20148CRITICALIn wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) codeEPSS 0.3%CVE-2020-9695HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-10899HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-10900HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-54210HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2021-33124MEDIUMOut-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aesEPSS 0.3%CVE-2025-10888HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2024-43097HIGHIn resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation EPSS 0.3%CVE-2025-10898HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-54213HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-68967HIGHOut-of-bounds Write in Bendix EC80 Brake ECUEPSS 0.3%CVE-2026-35195MEDIUMWasmtime has an out-of-bounds write or crash when transcoding component model stringsEPSS 0.3%CVE-2019-25631HIGHAIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2019-25633HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2024-23234HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, EPSS 0.3%CVE-2026-34682HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.3%