Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2023-30371CRITICALIn Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.EPSS 0.8%CVE-2023-30368CRITICALTenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.EPSS 0.8%CVE-2023-40308HIGHMemory Corruption vulnerability in SAP CommonCryptoLibEPSS 0.8%CVE-2026-16975HIGHIBM i is Affected By A Remote Code Execution Vulnerability []EPSS 0.8%CVE-2026-17223HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.8%CVE-2024-57581CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.EPSS 0.8%CVE-2023-29090MEDIUMAn issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos EPSS 0.8%CVE-2018-10878MEDIUMA flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecifiedEPSS 0.8%CVE-2024-57582CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.EPSS 0.8%CVE-2023-29088MEDIUMAn issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos EPSS 0.8%CVE-2021-39990CRITICALThe screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experieEPSS 0.8%CVE-2026-7372CRITICALGeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerabilityEPSS 0.8%CVE-2021-40226HIGHxpdfreader 4.03 is vulnerable to Buffer Overflow.EPSS 0.8%CVE-2024-30349HIGHFoxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-2505HIGHMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2023-31567HIGHPodofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.EPSS 0.7%CVE-2022-44755CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2026-26011CRITICALCritical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance -- Potential Remote Code ExecutionEPSS 0.7%CVE-2024-20375HIGHA vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications MaEPSS 0.7%CVE-2025-62550HIGHAzure Monitor Agent Remote Code Execution VulnerabilityEPSS 0.7%