Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-44363CRITICALTenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.EPSS 0.8%CVE-2026-54626CRITICALSAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)EPSS 0.8%CVE-2024-28553CRITICALTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.EPSS 0.8%CVE-2026-42944HIGHHeap overflow with multiple NSID, COOKIE, PADDING EDNS optionsEPSS 0.8%CVE-2026-54627CRITICALSAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)EPSS 0.8%CVE-2022-47116HIGHTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.EPSS 0.8%CVE-2023-4585HIGHMemory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2EPSS 0.8%CVE-2024-41311HIGHIn Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can leaEPSS 0.8%CVE-2022-35054MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.EPSS 0.8%CVE-2022-35052MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b84b1.EPSS 0.8%CVE-2022-35045MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0d63.EPSS 0.8%CVE-2022-35056MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0478.EPSS 0.8%CVE-2022-35046MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0466.EPSS 0.8%CVE-2022-35053MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.EPSS 0.8%CVE-2022-35055MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.EPSS 0.8%CVE-2022-35047MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.EPSS 0.8%CVE-2022-35058MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05ce.EPSS 0.8%CVE-2022-35050MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.EPSS 0.8%CVE-2022-35048MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0b2c.EPSS 0.8%CVE-2026-58188HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental pluginsEPSS 0.8%