Fallos del tipo CWE-787

5210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-20471MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker hasEPSS 0.2%CVE-2024-22103MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%CVE-2023-32203HIGHHorner Automation Cscape Out-of-bounds WriteEPSS 0.2%CVE-2023-24993HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2026-14612MEDIUMFreeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorizationEPSS 0.2%CVE-2023-24984HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24982HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-29160HIGHStack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive infoEPSS 0.2%CVE-2023-24980HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-37248HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2023-27385HIGHHeap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbEPSS 0.2%CVE-2023-24981HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2025-54208HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-1274HIGHRCS File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2026-12528MEDIUM389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()EPSS 0.2%CVE-2023-24988HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24979HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24990HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2026-55577MEDIUMImageMagick: Heap Buffer Overflow in ImageMagick MVG decoderEPSS 0.2%CVE-2023-24994HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%