Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2018-25216MEDIUMAnyBurn 4.3 Denial of Service Local Buffer OverflowEPSS 0.2%CVE-2026-42250MEDIUMOff-by-One Leading to Out-of-Bounds Write in bzip2EPSS 0.2%CVE-2024-24581MEDIUMArkcompiler runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2022-20600HIGHIn TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with SysteEPSS 0.2%CVE-2026-14986MEDIUMOut-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transactionEPSS 0.2%CVE-2026-13215MEDIUMZephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem imageEPSS 0.2%CVE-2026-71969HIGHOP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt OperationsEPSS 0.2%CVE-2026-45253HIGHMissing validation in ptrace(PT_SC_REMOTE)EPSS 0.2%CVE-2023-33877LOWOut-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticateEPSS 0.2%CVE-2022-20596MEDIUMIn sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.2%CVE-2022-20564MEDIUMIn _ufdt_output_strtab_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead tEPSS 0.2%CVE-2019-25561MEDIUMLyric Maker 2.0.1.0 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2022-20569MEDIUMIn thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This coEPSS 0.2%CVE-2026-45328CRITICALESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2022-20594MEDIUMIn updateStart of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalEPSS 0.2%CVE-2018-25267MEDIUMUltraISO 9.7.1.3519 Buffer Overflow via Output FileNameEPSS 0.2%CVE-2022-20577MEDIUMIn OemSimAuthRequest::encode of wlandata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 0.2%CVE-2021-46772LOWInsufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the strucEPSS 0.2%CVE-2022-20579MEDIUMIn RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could leaEPSS 0.2%CVE-2018-25262MEDIUMAngry IP Scanner for Linux 3.5.3 Denial of ServiceEPSS 0.2%