Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-2044HIGHMOXA NPort 5110 Out-of-bounds WriteEPSS 0.7%CVE-2026-42484CRITICALA heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or EPSS 0.7%CVE-2026-85452HIGHMOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS IdentifiersEPSS 0.7%CVE-2024-1913HIGH An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execEPSS 0.7%CVE-2023-51084CRITICALhyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.EPSS 0.7%CVE-2019-25654HIGHCore FTP/SFTP Server 1.2 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2025-12195HIGHWatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec ConfigurationEPSS 0.7%CVE-2023-5406MEDIUMServer communication with a controller can lead to remote code execution using a specially crafted message from the controller. See HoneywelEPSS 0.7%CVE-2026-48773CRITICALProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handlingEPSS 0.7%CVE-2019-25600HIGHUltraVNC Viewer 1.2.2.4 Denial of Service via Buffer OverflowEPSS 0.7%CVE-2026-22858MEDIUMFreeRDP has a global-buffer-overflow in crypto_base64_decodeEPSS 0.7%CVE-2024-44375HIGHD-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.EPSS 0.7%CVE-2026-4699HIGHIncorrect boundary conditions in the Layout: Text and Fonts componentEPSS 0.7%CVE-2026-4685HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.7%CVE-2025-5099CRITICALKL-001-2025-004: Mobile Dynamix PrinterShare Mobile Print Out-of-bounds WriteEPSS 0.7%CVE-2026-4697HIGHIncorrect boundary conditions in the Audio/Video: Web Codecs componentEPSS 0.7%CVE-2022-44752CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2022-44754CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView.EPSS 0.7%CVE-2022-44751CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2022-44753CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.7%