Fallos del tipo CWE-787

5210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-39148—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2022-39155—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2024-45469HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2024-45471HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2023-0249HIGHCVE-2023-0249EPSS 0.3%CVE-2023-32804—Mali GPU Userspace Driver can make an Out-of-Bounds accessEPSS 0.3%CVE-2022-47908HIGHStack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or executeEPSS 0.3%CVE-2018-9470HIGHIn bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote eEPSS 0.3%CVE-2026-18460MEDIUMOff-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.EPSS 0.3%CVE-2026-102761CRITICALNetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the lEPSS 0.3%CVE-2023-0969LOWGlobal read overflow in Z/IP GatewayEPSS 0.3%CVE-2026-12019HIGHHeap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised EPSS 0.3%CVE-2023-27933MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 1EPSS 0.3%CVE-2026-12314HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2022-43509HIGHOut-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary codeEPSS 0.3%CVE-2025-47725HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%CVE-2026-40003MEDIUMUSB-based arbitrary memory write vulnerability in ZTE ZX297520V3 soc BootROMEPSS 0.3%CVE-2025-47726HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%CVE-2025-47727HIGHOut-of-bounds Write in CNCSoftEPSS 0.3%CVE-2026-12310HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%