Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-22211MEDIUMTinyOS <= 2.1.2 Global Buffer Overflow in printfUARTEPSS 0.2%CVE-2026-77118HIGHOut-of-bounds write in GraphicsMagick PCD decoderEPSS 0.2%CVE-2024-40810MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cEPSS 0.2%CVE-2022-42509MEDIUMIn CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locEPSS 0.2%CVE-2022-42507MEDIUMIn ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds chEPSS 0.2%CVE-2026-88048HIGHTesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatchEPSS 0.2%CVE-2026-57260HIGHSecurity vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)EPSS 0.2%CVE-2026-86901HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciouslEPSS 0.2%CVE-2026-86313HIGHOut-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a665EPSS 0.2%CVE-2026-33850HIGHOut-of-bounds Write in WujekFoliarz DualSenseY-v2EPSS 0.2%CVE-2026-55892MEDIUMVim: Out-of-bounds Write in Spell File Prefix DumpEPSS 0.2%CVE-2025-24309LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2025-22835LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-10682MEDIUMOut-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspaceEPSS 0.2%CVE-2026-43903HIGHOpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release buildsEPSS 0.2%CVE-2026-17100HIGHPower System Out-of-bounds WriteEPSS 0.2%CVE-2025-27132LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2024-47797HIGHLiteos_a has an out-of-bounds Write vulnerabilityEPSS 0.2%CVE-2025-23240LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2024-47137HIGHLiteos_a has an out-of-bounds Write vulnerabilityEPSS 0.2%