Fallos del tipo CWE-787

5229 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-55332MEDIUMIn multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%CVE-2023-20604MEDIUMIn ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2022-32634MEDIUMIn ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2023-20701MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-32806MEDIUMIn wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege wEPSS 0.1%CVE-2024-22005HIGHthere is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additionalEPSS 0.1%CVE-2025-48540HIGHIn processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead EPSS 0.1%CVE-2022-32625MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-20700MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-20837MEDIUMIn seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2023-32811MEDIUMIn connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalationEPSS 0.1%CVE-2023-20931HIGHIn avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to locaEPSS 0.1%CVE-2025-48624HIGHIn multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local eEPSS 0.1%CVE-2023-21046MEDIUMIn ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2022-32626MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2026-0119MEDIUMIn usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physicEPSS 0.1%CVE-2022-47470MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with SystemEPSS 0.1%CVE-2026-55351HIGHIn VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-21051MEDIUMIn dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2026-55323HIGHIn gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%