Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-30983HIGHiccDEV has a stack buffer overflow in icFixXml()EPSS 0.2%CVE-2026-30987HIGHiccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()EPSS 0.2%CVE-2026-31795HIGHiccDEV has a stack buffer overflow write in CIccXform3DLut::Apply()EPSS 0.2%CVE-2023-3495HIGHOut-of-bounds Write Vulnerability in Hitachi EH-VIEW (KeypadDesigner)EPSS 0.2%CVE-2023-39985HIGHOut-of-bounds Write Vulnerability in Hitachi EH-VIEW (Designer)EPSS 0.2%CVE-2026-30985HIGHiccDEV has a heap-based buffer overflow write in CIccMatrixMath::SetRange()EPSS 0.2%CVE-2026-31796HIGHiccDEV has a heap-based buffer overflow in icCurvesFromXml()EPSS 0.2%CVE-2026-24193HIGHNVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful explEPSS 0.2%CVE-2023-0182HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of EPSS 0.2%CVE-2025-4877MEDIUMLibssh: write beyond bounds in binary to base64 conversion functionsEPSS 0.2%CVE-2025-30417HIGHOut of Bounds Write in Library!DecodeBase64() in NI Circuit Design SuiteEPSS 0.2%CVE-2025-30418HIGHOut of Bounds Write in CheckPins() in NI Circuit Design SuiteEPSS 0.2%CVE-2025-21966HIGHdm-flakey: Fix memory corruption in optional corrupt_bio_byte featureEPSS 0.2%CVE-2025-5917LOWLibarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.cEPSS 0.2%CVE-2024-27379MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-21312HIGHAudition | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-27376MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-21334HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2021-47765MEDIUMAbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)EPSS 0.2%CVE-2026-21335HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%