Fallos del tipo CWE-787

5210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-44178MEDIUMThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.EPSS 0.3%CVE-2025-54218HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-54216HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-54215HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-12199HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2026-18393MEDIUMFfmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursorEPSS 0.3%CVE-2025-54221HIGHInCopy | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-29786MEDIUMIn pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This couldEPSS 0.3%CVE-2026-41678HIGHrust-openssl: Incorrect bounds assertion in aes key wrapEPSS 0.3%CVE-2025-26479LOWDell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploEPSS 0.3%CVE-2022-42255MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lEPSS 0.3%CVE-2026-92869HIGHAn out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.EPSS 0.3%CVE-2026-11090MEDIUMUninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.3%CVE-2022-40103MEDIUMTenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers toEPSS 0.3%CVE-2023-2687LOWBuffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heEPSS 0.2%CVE-2023-27959HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrEPSS 0.2%CVE-2023-1078HIGHA flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the heEPSS 0.2%CVE-2024-39378HIGHAudition | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-7222HIGHLuxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-51454MEDIUMA Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to EPSS 0.2%