Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-24987HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2025-43402HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.1. AEPSS 0.2%CVE-2026-7923HIGHOut of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2019-25629HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via LoggingEPSS 0.2%CVE-2023-27400HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24992HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2024-20081CRITICALIn gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege EPSS 0.2%CVE-2023-24991HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-28401MEDIUMOut-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticEPSS 0.2%CVE-2025-43572HIGHDimension | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-24986HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24983HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-24989HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-5593HIGHThe out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could allow an authenticatedEPSS 0.2%CVE-2024-56695HIGHdrm/amdkfd: Use dynamic allocation for CU occupancy array in 'kfd_get_cu_occupancy()'EPSS 0.2%CVE-2025-54627HIGHOut-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.2%CVE-2023-44083HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2023-22670HIGHA heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw EPSS 0.2%CVE-2023-44082HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2022-50368HIGHdrm/msm/dsi: fix memory corruption with too many bridgesEPSS 0.2%