Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-31602MEDIUMNVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploEPSS 0.2%CVE-2024-47038CRITICALIn dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead tEPSS 0.2%CVE-2023-22613HIGHAn issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled addreEPSS 0.2%CVE-2025-54284HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-54283HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2021-26398HIGHInsufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AEPSS 0.2%CVE-2025-21131HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-21130HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-51778MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%CVE-2025-21138HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2021-29514LOWHeap out of bounds write in `RaggedBinCount`EPSS 0.2%CVE-2026-44663MEDIUMOpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflowEPSS 0.2%CVE-2025-21136HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-18295HIGHGStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2021-29558LOWHeap buffer overflow in `SparseSplit`EPSS 0.2%CVE-2026-47749HIGHstable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint filesEPSS 0.2%CVE-2024-12668HIGHVelocidex WinPmem Out of Bounds Write VulnerabilityEPSS 0.2%CVE-2025-7990HIGHAshlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-30102MEDIUMDell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker couEPSS 0.2%CVE-2025-61553HIGHAn out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows lEPSS 0.2%