Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2025-22831MEDIUMBuffer Overflow in NTFS when parsing the VOLUME_NAMEEPSS 0.1%CVE-2026-65609LOWOut-of-bounds write in nnnEPSS 0.1%CVE-2026-88049HIGHTesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatchEPSS 0.1%CVE-2025-22832MEDIUMBuffer Overflow in NTFS when parsing the ATTRIBUTE_LISTEPSS 0.1%CVE-2026-88050MEDIUMTesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code valuesEPSS 0.1%CVE-2026-84531MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27.EPSS 0.1%CVE-2025-42971MEDIUMMemory Corruption vulnerability in SAPCAREPSS 0.1%CVE-2026-25569HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SEPSS 0.1%CVE-2026-48724MEDIUMImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth ditheringEPSS 0.1%CVE-2026-24809MEDIUMSave stack space while handling errors in praydog/REFrameworkEPSS 0.1%CVE-2024-5679HIGHCWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor witEPSS 0.1%CVE-2026-53194HIGHUSB: serial: kl5kusb105: fix bulk-out buffer overflowEPSS 0.1%CVE-2026-55059MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerabilityEPSS 0.1%CVE-2026-75658HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2026-34238MEDIUMImageMagick: Integer overflow in despeckle operation causes heap buffer overflow on 32-bit buildsEPSS 0.1%CVE-2026-102566HIGHCTranslate2 before 4.8.1 Heap Buffer Overflow via model.binEPSS 0.1%CVE-2025-10451HIGHH19Int15CallbackSmm: SMM memory corruption vulnerability in combined DXE/SMM (SMRAM write)EPSS 0.1%CVE-2016-20037HIGHxwpe 1.5.30a-2.1 Stack-based Buffer OverflowEPSS 0.1%CVE-2026-46521MEDIUMImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compressionEPSS 0.1%CVE-2026-8916MEDIUMOut-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b04EPSS 0.1%