Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-21349HIGHLightroom Desktop | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2026-10587MEDIUMA potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System ManagemeEPSS 0.1%CVE-2023-20513LOWAn insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) tEPSS 0.1%CVE-2026-46145HIGHRDMA/mana: Validate rx_hash_key_lenEPSS 0.1%CVE-2025-24304LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.1%CVE-2026-78547MEDIUMOut-of-Bounds WriteEPSS 0.1%CVE-2026-21341HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2019-25604HIGHDVDXPlayer Pro 5.5 Local Buffer Overflow with SEHEPSS 0.1%CVE-2023-47252MEDIUMAn issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM commuEPSS 0.1%CVE-2016-20039HIGHMulti Emulator Super System 0.154-3.1 Buffer OverflowEPSS 0.1%CVE-2026-21346HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2024-34776LOWOut-of-bounds write in some Intel(R) SGX SDK software may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.1%CVE-2025-65001HIGHFujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.EPSS 0.1%CVE-2025-11266MEDIUMGrassroots DICOM (GDCM) Out-of-bounds WriteEPSS 0.1%CVE-2019-25659MEDIUMASPRunner Professional 6.0.766 Local Buffer Overflow DoSEPSS 0.1%CVE-2026-61389HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2026-24795MEDIUMAn Out-of-bounds Write in CloverHackyColor/CloverBootloaderEPSS 0.1%CVE-2026-60063HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2025-32022MEDIUMFinit has heap based buffer overwrite in urandom.so pluginEPSS 0.1%CVE-2026-20476MEDIUMIn ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User executioEPSS 0.1%