Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-68160MEDIUMHeap out-of-bounds write in BIO_f_linebuffer on short writesEPSS 0.2%CVE-2024-45185MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200,EPSS 0.2%CVE-2024-3900LOWOut-of-bounds stack array write in Xpdf 4.05 due to missing zero checkEPSS 0.2%CVE-2026-65704HIGHFFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten DecoderEPSS 0.2%CVE-2019-25550MEDIUMEncrypt PDF 2.3 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2022-33730MEDIUMHeap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical aEPSS 0.2%CVE-2022-42505MEDIUMIn ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrectEPSS 0.2%CVE-2022-42506MEDIUMIn SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local EPSS 0.2%CVE-2025-9340NONEnative encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.EPSS 0.2%CVE-2018-25266MEDIUMAngry IP Scanner 3.5.3 Denial of Service via Preferences Buffer OverflowEPSS 0.2%CVE-2026-10669HIGHXtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationEPSS 0.2%CVE-2022-42504MEDIUMIn CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This coulEPSS 0.2%CVE-2026-71974MEDIUMU-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition ReadEPSS 0.2%CVE-2016-20038HIGHyTree 1.94-1.1 Stack-Based Buffer OverflowEPSS 0.2%CVE-2018-25215MEDIUMExcel Password Recovery Professional 8.2.0.0 Local Buffer Overflow DoSEPSS 0.2%CVE-2026-21307HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-88053HIGHTesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddataEPSS 0.2%CVE-2024-22448MEDIUMDell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploiEPSS 0.2%CVE-2021-46779HIGHInsufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASPEPSS 0.2%CVE-2023-0186MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of EPSS 0.2%