Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-2569HIGH A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kerneEPSS 0.2%CVE-2026-20416HIGHIn pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a maliciEPSS 0.2%CVE-2026-68515HIGHOpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel unionEPSS 0.2%CVE-2019-25665MEDIUMRiver Past Ringtone Converter 2.7.6.1601 Buffer Overflow DoSEPSS 0.2%CVE-2026-20446MEDIUMIn sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker EPSS 0.2%CVE-2019-25546MEDIUMNetAware 1.20 Share Name Denial of ServiceEPSS 0.2%CVE-2025-1292MEDIUMTPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOSEPSS 0.2%CVE-2019-25667MEDIUMTaskInfo 8.2.0.280 Denial of Service Buffer OverflowEPSS 0.2%CVE-2019-25545MEDIUMTerminal Services Manager 3.2.1 Local Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2022-21804HIGHOut-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentiallEPSS 0.2%CVE-2019-25695HIGHR 3.4.4 Local Buffer Overflow Windows XP SP3EPSS 0.2%CVE-2025-24185MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, mEPSS 0.2%CVE-2023-21509MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to verEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2025-1924MEDIUMA vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciousEPSS 0.2%CVE-2026-84546HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2019-25547MEDIUMNetAware 1.20 Denial of Service via Add Block Buffer OverflowEPSS 0.2%CVE-2019-25569MEDIUMRealTerm Serial Terminal 2.0.0.70 SEH Overflow CrashEPSS 0.2%CVE-2023-21499HIGHOut-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attEPSS 0.2%CVE-2023-21508MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain KeystoreEPSS 0.2%