Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2021-47765MEDIUMAbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)EPSS 0.2%CVE-2026-18821HIGHPower System Out-of-bounds WriteEPSS 0.2%CVE-2026-21318HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-27379MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-21335HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-21312HIGHAudition | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-21506MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain KeEPSS 0.2%CVE-2026-0538HIGHGIF File Parsing Out-of-Bounds WriteEPSS 0.2%CVE-2024-7993HIGHOut-of-Bounds Write Vulnerability in Autodesk RevitEPSS 0.2%CVE-2026-33491HIGHZen-C has Stack-Based Buffer Overflow in Identifier ManglingEPSS 0.2%CVE-2018-9373HIGHIn TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remEPSS 0.2%CVE-2026-0661HIGHOut-of-Bounds Write in RGB File ParsingEPSS 0.2%CVE-2026-0537HIGHRGB File Parsing Memory CorruptionEPSS 0.2%CVE-2026-68513HIGHOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collisionEPSS 0.2%CVE-2026-54758HIGHNotepad++: Stack Buffer Overflow in expandNppEnvironmentStrsEPSS 0.2%CVE-2025-49572HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-54187HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-54692HIGHSAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write)EPSS 0.2%CVE-2025-49573HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-21678HIGHiccDEV has heap-buffer-overflow vulnerability on IccTagXml()EPSS 0.2%