Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-54789HIGHmod_auth_openidc has out-of-bounds read and write in state cookie parsingEPSS 0.7%CVE-2023-45985HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the functioEPSS 0.7%CVE-2026-44421HIGHFreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypassEPSS 0.7%CVE-2026-43790CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A EPSS 0.7%CVE-2024-7535HIGHInappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption EPSS 0.7%CVE-2024-25448HIGHAn issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafteEPSS 0.7%CVE-2026-37457HIGHAn off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stablEPSS 0.7%CVE-2025-0690MEDIUMGrub2: read: integer overflow may lead to out-of-bounds writeEPSS 0.7%CVE-2023-6931HIGHOut-of-bounds write in Linux kernel's Performance Events system componentEPSS 0.7%CVE-2021-47772HIGH10-Strike Network Inventory Explorer Pro 9.31 - Buffer Overflow (SEH)EPSS 0.7%CVE-2023-31488CRITICALHyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, CiscoEPSS 0.7%CVE-2023-33552HIGHHeap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code viaEPSS 0.7%CVE-2022-37937CRITICALPre-auth memory corruption in HPE ServiceguardEPSS 0.7%CVE-2022-34485CRITICALMozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of thesEPSS 0.7%CVE-2022-42932HIGHMozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some oEPSS 0.7%CVE-2022-4608HIGHA vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can onlyEPSS 0.7%CVE-2026-56786CRITICALRTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 MessageEPSS 0.7%CVE-2024-25200HIGHEspruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.EPSS 0.7%CVE-2023-26064CRITICALCertain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.EPSS 0.7%CVE-2020-27005—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%