Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-78183CRITICALDBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_floatEPSS 0.7%CVE-2024-32608CRITICALHDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial ofEPSS 0.7%CVE-2024-20066HIGHIn modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no addiEPSS 0.7%CVE-2024-41131HIGHOut-of-bounds Write in SixLabors ImageSharpEPSS 0.7%CVE-2023-25746HIGHMemory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effEPSS 0.7%CVE-2023-0930HIGHHeap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.7%CVE-2016-20049CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer Overflow Remote Code ExecutionEPSS 0.7%CVE-2017-20227CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer OverflowEPSS 0.7%CVE-2023-25745HIGHMemory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.7%CVE-2024-35797HIGHmm: cachestat: fix two shmem bugsEPSS 0.7%CVE-2023-26551MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a clieEPSS 0.7%CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS 0.7%CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS 0.7%CVE-2025-41679MEDIUMUnauthenticated Buffer Overflow in Conftool Service Leading to Denial of ServiceEPSS 0.7%CVE-2026-23876HIGHHeap buffer overflow with attacker-controlled data in XBM parserEPSS 0.7%CVE-2024-35273HIGHA out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escEPSS 0.7%CVE-2025-49709CRITICALMemory corruption in canvas surfacesEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2022-36320CRITICALMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2022-41193—Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusEPSS 0.7%