Fallos del tipo CWE-787

5225 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-20493MEDIUMIn wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious acEPSS 0.1%CVE-2024-45382LOWLiteos_a has an Out-of-bounds Write vulnerabilityEPSS 0.1%CVE-2026-63388HIGHLibevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX acceptEPSS 0.1%CVE-2026-13196HIGHOut-of-bounds Write in KUNBUS piControlEPSS 0.1%CVE-2026-47529MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. EPSS 0.1%CVE-2026-47538MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds writEPSS 0.1%CVE-2025-29949MEDIUMInsufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to wEPSS 0.1%CVE-2026-47509MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-boundsEPSS 0.1%CVE-2025-48518MEDIUMImproper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integEPSS 0.1%CVE-2025-26403MEDIUMOut-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a priviEPSS 0.1%CVE-2026-47537MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. EPSS 0.1%CVE-2026-47532MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-boEPSS 0.1%CVE-2019-25474MEDIUMEasy MP3 Downloader 4.7.8.8 Denial of Service Buffer OverflowEPSS 0.1%CVE-2026-14063MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive informatioEPSS 0.1%CVE-2026-21362HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2018-25222HIGHSC v7.16 Stack-Based Buffer Overflow Remote Code ExecutionEPSS 0.1%CVE-2026-17572MEDIUMHDF5 SOHM List Index Heap Buffer OverflowEPSS 0.1%CVE-2026-33535MEDIUMImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interactionEPSS 0.1%CVE-2022-32620MEDIUMIn mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution pEPSS 0.1%CVE-2026-18739LOWPopt-devel: popt-static: off-by-one in poptstuffargsEPSS 0.1%