Fallos del tipo CWE-787

5212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2019-25659MEDIUMASPRunner Professional 6.0.766 Local Buffer Overflow DoSEPSS 0.1%CVE-2026-60063HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2025-11266MEDIUMGrassroots DICOM (GDCM) Out-of-bounds WriteEPSS 0.1%CVE-2025-7004HIGHAvast antivirus heap buffer OOB write when scanning a malformed PE fileEPSS 0.1%CVE-2026-24795MEDIUMAn Out-of-bounds Write in CloverHackyColor/CloverBootloaderEPSS 0.1%CVE-2025-32022MEDIUMFinit has heap based buffer overwrite in urandom.so pluginEPSS 0.1%CVE-2026-47501HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supEPSS 0.1%CVE-2026-20478MEDIUMIn Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User exEPSS 0.1%CVE-2024-45555HIGHInteger Overflow to Buffer Overflow in Automotive OS PlatformEPSS 0.1%CVE-2025-58150HIGHx86: buffer overrun with shadow paging + tracingEPSS 0.1%CVE-2016-20042HIGHTRN 3.6-23 Stack Buffer Overflow Local Code ExecutionEPSS 0.1%CVE-2023-22351MEDIUMOut-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege EPSS 0.1%CVE-2026-70628HIGHFFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV FileEPSS 0.1%CVE-2019-25612HIGHAdmin Express 1.2.5.485 Local SEH Buffer Overflow via Folder PathEPSS 0.1%CVE-2026-18374MEDIUMPassing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library versioEPSS 0.1%CVE-2026-102474MEDIUMDash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservationEPSS 0.1%CVE-2025-39818HIGHHID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs saveEPSS 0.1%CVE-2026-4407LOWOut-of-bounds array write in Xpdf 4.06 due to missing validationEPSS 0.1%CVE-2026-20493MEDIUMIn wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious acEPSS 0.1%CVE-2026-24201MEDIUMNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successfulEPSS 0.1%