Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2019-25701HIGHEasy Video to iPod Converter 1.6.20 Local Buffer Overflow SEHEPSS 0.2%CVE-2024-8596HIGHAutodesk AutoCAD MODEL File Parsing Out-Of-Bounds Write Code Execution VulnerabilityEPSS 0.2%CVE-2026-17469MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]EPSS 0.2%CVE-2025-61828HIGHIllustrator on iPad | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-54243HIGHSubstance3D - Viewer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-49039MEDIUMOut-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users witEPSS 0.2%CVE-2022-31699LOWVMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit EPSS 0.2%CVE-2025-54245HIGHSubstance3D - Viewer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-43353MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. ProcessinEPSS 0.2%CVE-2019-25689HIGHHTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEHEPSS 0.2%CVE-2026-63422HIGHOpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds writeEPSS 0.2%CVE-2024-23803HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < VEPSS 0.2%CVE-2016-20045HIGHHNB Organizer 1.9.18-10 Local Buffer Overflow via -rc ParameterEPSS 0.2%CVE-2023-46931MEDIUMGPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in EPSS 0.2%CVE-2026-103111HIGHPCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arEPSS 0.2%CVE-2023-46927MEDIUMGPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gEPSS 0.2%CVE-2023-25952MEDIUMOut-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enabEPSS 0.2%CVE-2023-46928MEDIUMGPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:4EPSS 0.2%CVE-2023-46930MEDIUMGPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:EPSS 0.2%CVE-2018-25212HIGHBoxoft wav-wma Converter 1.0 Local Buffer Overflow SEHEPSS 0.2%