Fallos del tipo CWE-787

5210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-0957HIGHOut-Of-Bounds Write in Digilent DASYLabEPSS 0.2%CVE-2025-24442HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22327MEDIUMOut-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable inforEPSS 0.2%CVE-2025-24441HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2019-25660MEDIUMLanHelper 1.74 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2025-21919HIGHsched/fair: Fix potential memory corruption in child_cfs_rq_on_listEPSS 0.2%CVE-2025-24444HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22612HIGHAn issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler wiEPSS 0.2%CVE-2025-24445HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-47317HIGHOut-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitraEPSS 0.2%CVE-2024-53193HIGHclk: clk-loongson2: Fix memory corruption bug in struct loongson2_clk_providerEPSS 0.2%CVE-2024-22103MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%CVE-2024-54520MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura EPSS 0.2%CVE-2026-20471MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker hasEPSS 0.2%CVE-2026-14368MEDIUMOff-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parserEPSS 0.2%CVE-2017-13313HIGHIn ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due tEPSS 0.2%CVE-2021-25492HIGHLack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.EPSS 0.2%CVE-2023-32203HIGHHorner Automation Cscape Out-of-bounds WriteEPSS 0.2%CVE-2020-37140MEDIUMEverest 5.50.2100 - 'Open File' Denial of ServiceEPSS 0.2%CVE-2024-11920MEDIUMInappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memorEPSS 0.2%