Fallos del tipo CWE-787

5145 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-24094HIGHAn issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.EPSS 0.8%CVE-2022-45766CRITICALHardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remotEPSS 0.8%CVE-2022-43027CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewaEPSS 0.8%CVE-2022-43025CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServeEPSS 0.8%CVE-2022-43029CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.EPSS 0.8%CVE-2022-43028CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCEPSS 0.8%CVE-2022-43026CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCEPSS 0.8%CVE-2022-43024CRITICALTenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServeEPSS 0.8%CVE-2022-27653—A vulnerability has been identified in Simcenter Femap (All versions < V2022.2). The affected application contains an out of bounds write paEPSS 0.8%CVE-2026-73514HIGHPostGIS address_standardizer Out-of-Bounds Write via standardize_address()EPSS 0.8%CVE-2026-43810CRITICALThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOEPSS 0.8%CVE-2026-43803CRITICALAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.8%CVE-2023-7244CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2026-78524HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-7243CRITICALEthercat Zeek Plugin Out-of-bounds WriteEPSS 0.8%CVE-2023-0847MEDIUM The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write prior to implementatEPSS 0.8%CVE-2026-33721MEDIUMMapServer has heap buffer overflow in SLD `Categorize` Threshold parsingEPSS 0.8%CVE-2024-2184CRITICALBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may alloEPSS 0.8%CVE-2023-33551HIGHHeap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary cEPSS 0.8%CVE-2023-34940HIGHAsus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerabiliEPSS 0.8%