Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2021-39793HIGHIn kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could leaEPSS 0.7%KEVCVE-2022-44751CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2026-11771HIGHOpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentiEPSS 0.7%CVE-2022-48322CRITICALNETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.EPSS 0.7%CVE-2024-9419HIGHCertain HP Print Products–Potential Remote Code Execution and/or Elevation of Privilege with the HP Smart Universal Printing DriverEPSS 0.7%CVE-2026-93452HIGHsnappy-java through 1.1.10.8 Buffer Overflow in Snappy.compressEPSS 0.7%CVE-2024-52531MEDIUMGNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict.EPSS 0.7%CVE-2019-19332MEDIUMAn out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor haEPSS 0.7%CVE-2024-57579CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.EPSS 0.7%CVE-2019-25362CRITICALWMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlowEPSS 0.7%CVE-2023-29929HIGHBuffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service vEPSS 0.7%CVE-2022-42498CRITICALIn Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution EPSS 0.7%CVE-2024-0143MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted EPSS 0.7%CVE-2022-38582MEDIUMIncorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.EPSS 0.7%CVE-2026-3342HIGHWatchGuard Firebox Out of Bounds Write VulnerabilityEPSS 0.7%CVE-2026-46195CRITICALsmb: client: validate dacloffset before building DACL pointersEPSS 0.7%CVE-2025-70290CRITICALAn issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by mEPSS 0.7%CVE-2026-17206HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.7%CVE-2020-15214HIGHOut of bounds write in tensorflow-liteEPSS 0.7%CVE-2026-21047HIGHOut-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.EPSS 0.7%