Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2016-20043HIGHNRSS RSS Reader 0.3.9-1 Stack Buffer OverflowEPSS 0.2%CVE-2024-7671HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2024-37676HIGHAn issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.EPSS 0.2%CVE-2026-1335HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.2%CVE-2019-25670HIGHRiver Past Video Cleaner 7.6.3 Buffer Overflow via SEHEPSS 0.2%CVE-2026-47747HIGHstable-diffusion.cpp has a Heap-based Buffer OverflowEPSS 0.2%CVE-2018-25256MEDIUMIP TOOLS 2.50 Local Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2024-48241MEDIUMAn issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.EPSS 0.2%CVE-2026-46331HIGHnet/sched: fix pedit partial COW leading to page cache corruptionEPSS 0.2%CVE-2025-2632HIGHOut of Bounds Write Vulnerability in NI LabVIEW reading CPU info from cacheEPSS 0.2%CVE-2026-70632HIGHFFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI DemuxingEPSS 0.2%CVE-2024-56784HIGHdrm/amd/display: Adding array index check to prevent memory corruptionEPSS 0.2%CVE-2023-39427HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%CVE-2023-39943HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%CVE-2026-0954HIGHOut-Of-Bounds Write When Opening a Corrupt DSB File in Digilent DASYLabEPSS 0.2%CVE-2026-50264HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformatEPSS 0.2%CVE-2026-47750HIGHstable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint filesEPSS 0.2%CVE-2025-2631HIGHOut of Bounds Write Vulnerability in NI LabVIEW in InitCPUInformation()EPSS 0.2%CVE-2026-81878MEDIUMradare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parserEPSS 0.2%CVE-2023-49128HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounEPSS 0.2%