Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-81893MEDIUMGdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recoveryEPSS 0.2%CVE-2026-25781HIGHkernel_liteos_a has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-59857MEDIUMVim: Out-of-bounds Write in SAL SoundfoldingEPSS 0.2%CVE-2018-9340HIGHIn ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, cauEPSS 0.2%CVE-2022-41592LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-58304MEDIUMOut-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:EPSS 0.2%CVE-2022-41598LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41595LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41593LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2025-39917HIGHbpf: Fix out-of-bounds dynptr write in bpf_crypto_cryptEPSS 0.2%CVE-2019-25466HIGHEasy File Sharing Web Server 7.2 Local SEH OverflowEPSS 0.2%CVE-2022-41603LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2023-53320HIGHscsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info()EPSS 0.2%CVE-2019-25607HIGHAxessh 4.2 Local Stack-based Buffer Overflow via Log File NameEPSS 0.2%CVE-2016-20046HIGHzFTP Client 20061220+dfsg3-4.1 Local Buffer OverflowEPSS 0.1%CVE-2019-25611HIGHMiniFtp parseconf_load_setting Buffer Overflow via ConfigurationEPSS 0.1%CVE-2016-20047HIGHEKG Gadu 1.9 Local Buffer Overflow via Username ParameterEPSS 0.1%CVE-2025-22832MEDIUMBuffer Overflow in NTFS when parsing the ATTRIBUTE_LISTEPSS 0.1%CVE-2017-20226HIGHMapscrn 2.0.3 Stack-Based Buffer OverflowEPSS 0.1%CVE-2026-88050MEDIUMTesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code valuesEPSS 0.1%