Fallos del tipo CWE-787

5228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-20412HIGHIn cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2026-10719LOWOpen Seachest/Seachest NVMe show Format Descriptors VulnerabilityEPSS 0.1%CVE-2024-20142MEDIUMIn V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2023-32812MEDIUMIn gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges EPSS 0.1%CVE-2025-20639MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2026-20409HIGHIn imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a maliEPSS 0.1%CVE-2024-29740HIGHIn tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of priEPSS 0.1%CVE-2025-20635MEDIUMIn V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attEPSS 0.1%CVE-2026-10717LOWOpen-Seachest/Seachest show SCSI Defect List VulnerabilityEPSS 0.1%CVE-2026-20456MEDIUMIn wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User exeEPSS 0.1%CVE-2025-20642MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2024-20024MEDIUMIn flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System eEPSS 0.1%CVE-2026-28583HIGHIn validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. ThisEPSS 0.1%CVE-2026-0819LOWStack buffer overflow in PKCS7 SignedData encoding with custom signed attributesEPSS 0.1%CVE-2026-55301HIGHIn Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation oEPSS 0.1%CVE-2023-21040HIGHIn buildCommand of bluetooth_ccc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escaEPSS 0.1%CVE-2024-31336HIGHIn PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This EPSS 0.1%CVE-2021-0699HIGHIn HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege EPSS 0.1%CVE-2025-54616MEDIUMOut-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2023-20615MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%