Fallos del tipo CWE-787

5228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2024-20027HIGHIn da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2023-32854MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2026-21085HIGHOut-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.EPSS 0.1%CVE-2026-20714HIGHOut-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escaEPSS 0.1%CVE-2026-4430MEDIUMHeap Buffer Overflow in AgileEngineEPSS 0.1%CVE-2026-102004HIGHVxWorks 7EPSS 0.1%CVE-2023-32882MEDIUMIn battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2024-45543MEDIUMOut-of-bounds Write in AudioEPSS 0.1%CVE-2024-20143MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2024-20145MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2025-29933MEDIUMImproper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of EPSS 0.1%CVE-2024-20144MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2025-20650MEDIUMIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2026-17051MEDIUMOut-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell lengthEPSS 0.1%CVE-2026-13467HIGHSystemic Missing Address Validation in SiP SMC HandlersEPSS 0.1%CVE-2026-63273MEDIUMHeap buffer overflow in PDF import encryption handlingEPSS 0.1%CVE-2026-20455HIGHIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2026-0799HIGHOOBR and OOBW in libpcap before 1.10.7EPSS 0.1%CVE-2025-46585HIGHOut-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availabilEPSS 0.1%CVE-2026-21110MEDIUMOut-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.EPSS 0.1%