Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-43774MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2023-32466MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with higEPSS 0.2%CVE-2023-21085HIGHIn nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remoteEPSS 0.2%CVE-2026-49839HIGHjq --rawfile invalid-state reuse after String too long causes heap-buffer-overflowEPSS 0.2%CVE-2026-58087HIGHHeap out-of-bounds access in semctl(2)EPSS 0.2%CVE-2024-22273HIGHThe storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access tEPSS 0.2%CVE-2025-11795HIGHJPG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2025-65086HIGHOut-of-bounds write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2026-21305HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-38665MEDIUMOut-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.2%CVE-2024-4976LOWOut-of-bounds array write in Xpdf 4.05 due to missing object type checkEPSS 0.2%CVE-2024-27370MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-59948HIGHComposer: Arbitrary file write outside vendor via malicious transitive package nameEPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2024-27383MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-64725HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.2%CVE-2026-8718HIGHOut-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLSEPSS 0.2%CVE-2026-62291MEDIUMlibheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensionsEPSS 0.2%CVE-2024-27373MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-53705HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Out-of-bounds WriteEPSS 0.2%