Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2018-25218HIGHPassFab RAR Password Recovery 9.3.2 SEH Buffer OverflowEPSS 0.2%CVE-2022-50368HIGHdrm/msm/dsi: fix memory corruption with too many bridgesEPSS 0.2%CVE-2026-0536HIGHGIF File Parsing Stack Based Buffer OverflowEPSS 0.2%CVE-2025-21165HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2019-25619HIGHFTP Shell Server 6.83 Buffer Overflow via Account NameEPSS 0.2%CVE-2026-21504MEDIUMHeap Buffer Overflow in iccDEV ToneMap ParserEPSS 0.2%CVE-2026-11690HIGHOut of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2025-21166HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-21164HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2018-25260HIGHMAGIX Music Editor 3.1 Buffer Overflow via SEHEPSS 0.2%CVE-2024-55413HIGHA vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arEPSS 0.2%CVE-2025-64503MEDIUM[BIGSLEEP-434615384] cups-filters 1.x: out of bounds write in pdftorasterEPSS 0.2%CVE-2024-53098HIGHdrm/xe/ufence: Prefetch ufence addr to catch bogus addressEPSS 0.2%CVE-2024-32668HIGHbhyve(8) privileged guest escape via USB controllerEPSS 0.2%CVE-2026-41970MEDIUMOut-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect avEPSS 0.2%CVE-2024-45183MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leadsEPSS 0.2%CVE-2022-31602MEDIUMNVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploEPSS 0.2%CVE-2025-21131HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-21130HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-54284HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%