Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-59732HIGHHeap-buffer-overflow write in FFmpeg EXR dwa_uncompressEPSS 0.2%CVE-2025-39862HIGHwifi: mt76: mt7915: fix list corruption after hardware restartEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2023-21508MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain KeystoreEPSS 0.2%CVE-2023-21499HIGHOut-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attEPSS 0.2%CVE-2019-25569MEDIUMRealTerm Serial Terminal 2.0.0.70 SEH Overflow CrashEPSS 0.2%CVE-2023-21509MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to verEPSS 0.2%CVE-2019-25615HIGHLavavo CD Ripper 4.20 Local SEH Buffer OverflowEPSS 0.2%CVE-2026-21306HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-25480HIGHVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card ReadEPSS 0.2%CVE-2023-20941MEDIUMIn acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to phyEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2026-33317HIGHOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosureEPSS 0.2%CVE-2026-40310MEDIUMImageMagick: Heap out-of-bounds write in JP2 encoderEPSS 0.2%CVE-2023-40307MEDIUMPrivileges Memory Corruption (Out-of-bound write)EPSS 0.2%CVE-2019-25584MEDIUMRarmaRadio 2.72.3 Server Field Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-32861HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass fileEPSS 0.2%CVE-2026-64204HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2019-25556MEDIUMTwistedBrush Pro Studio 24.06 Resize Image Denial of ServiceEPSS 0.2%CVE-2026-32862HIGHOut-of-Bounds Write in ResFileFactory::InitResourceMgr()EPSS 0.2%