Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2022-32810HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. AnEPSS 0.7%CVE-2026-12844HIGHList::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise functionEPSS 0.7%CVE-2024-36761CRITICALnaga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.EPSS 0.7%CVE-2026-59205HIGHPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatchEPSS 0.7%CVE-2026-8053HIGHFlatBSON Duplicate Field Index DriftEPSS 0.7%CVE-2026-59199HIGHPillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowEPSS 0.7%CVE-2022-23092HIGHMissing bounds check in 9p message handlingEPSS 0.7%CVE-2026-96891CRITICALD-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds writeEPSS 0.7%CVE-2022-43034MEDIUMAn issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) funEPSS 0.7%CVE-2022-43035MEDIUMAn issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to aEPSS 0.7%CVE-2022-28318HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. EPSS 0.7%CVE-2023-50711MEDIUM`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory accessEPSS 0.7%CVE-2023-25078CRITICALDoS due to heap overflowEPSS 0.7%CVE-2023-23585CRITICALServer DoS due to heap overflowEPSS 0.7%CVE-2024-23122HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.7%CVE-2024-23978CRITICALHeap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be exeEPSS 0.7%CVE-2024-21780HIGHStack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in aEPSS 0.7%CVE-2026-73193CRITICALDBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparseEPSS 0.6%CVE-2024-32669MEDIUMPossible stack overflow due to a string encoding processing errorEPSS 0.6%CVE-2025-30356CRITICALHeap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`EPSS 0.6%