Fallos del tipo CWE-787

5210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2017-20228HIGHFlat Assembler 1.71.21 Stack-Based Buffer Overflow ROPEPSS 0.2%CVE-2025-43594HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43548HIGHDimension | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-27197HIGHLightroom Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-38610HIGHA memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An apEPSS 0.2%CVE-2025-49530HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-49526HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43554HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43569HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-24992HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24991HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2025-43572HIGHDimension | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43402HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.1. AEPSS 0.2%CVE-2023-24989HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24987HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2019-25629HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via LoggingEPSS 0.2%CVE-2023-24983HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2024-20081CRITICALIn gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege EPSS 0.2%CVE-2025-1122MEDIUMOut-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gaEPSS 0.2%CVE-2023-28401MEDIUMOut-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticEPSS 0.2%