Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-58188HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental pluginsEPSS 0.8%CVE-2024-7973HIGHHeap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read viaEPSS 0.8%CVE-2023-35110HIGHAn issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that EPSS 0.8%CVE-2023-34612HIGHAn issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object thaEPSS 0.8%CVE-2026-32875HIGHUltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loopEPSS 0.8%CVE-2025-20634HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has conneEPSS 0.8%CVE-2023-48111HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulneraEPSS 0.8%CVE-2022-45689HIGHhutool-json v5.8.10 was discovered to contain an out of memory error.EPSS 0.8%CVE-2023-48110HIGHTenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerabEPSS 0.8%CVE-2022-41989CRITICALCVE-2022-41989EPSS 0.8%CVE-2024-57580CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.EPSS 0.8%CVE-2023-50986HIGHTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.EPSS 0.8%CVE-2022-37453HIGHAn issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and EPSS 0.8%CVE-2022-35049MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.EPSS 0.8%CVE-2022-35059MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0414.EPSS 0.8%CVE-2018-10881MEDIUMA flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denEPSS 0.8%CVE-2026-3849MEDIUMBuffer Overflow in HPKE via Oversized ECH ConfigEPSS 0.8%CVE-2024-52963LOWA out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4EPSS 0.8%CVE-2024-30348HIGHFoxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-30355HIGHFoxit PDF Reader AcroForm Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%