Fallos del tipo CWE-787

5146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em uma posição de memória fora do intervalo alocado para um buffer, array ou estrutura. O atacante aproveita para sobrescrever dados adjacentes (variáveis, ponteiros, pilha de retorno), alterando o comportamento da aplicação ou assumindo controle total do sistema.

Ejemplo

Um programa lê 256 bytes de entrada do usuário e copia para um buffer de 64 bytes sem validação. O atacante envia 300 bytes, que transbordam o buffer e sobrescrevem o endereço de retorno na pilha, permitindo execução de código arbitrário.

Cómo mitigar

Sempre validar tamanho de entrada contra o limite do buffer antes de copiar (usar strncpy, snprintf em vez de strcpy, sprintf). Em linguagens modernas, usar estruturas bounds-checked (Rust, C# arrays) ou linters que detectem padrões perigosos.

CVE-2026-19773CRITICALlibwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-53266HIGHnetfilter: bridge: make ebt_snat ARP rewrite writableEPSS 0.6%KEVCVE-2023-48194MEDIUMVulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qosEPSS 0.6%CVE-2023-1945MEDIUMUnexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerabilEPSS 0.6%CVE-2024-39840HIGHFactorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain EPSS 0.6%CVE-2026-56340HIGHvLLM - Denial of Service via Unvalidated Multimodal EmbeddingsEPSS 0.6%CVE-2026-56209HIGHLibaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijackEPSS 0.6%CVE-2026-13053HIGHWatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command HandlerEPSS 0.6%CVE-2026-13050HIGHWatchGuard Firebox networkd Out of Bounds Write VulnerabilityEPSS 0.6%CVE-2024-29176HIGHDell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacEPSS 0.6%CVE-2026-34265CRITICALMemory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP PlatformEPSS 0.6%CVE-2026-24253HIGHNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerabEPSS 0.6%CVE-2024-0142MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted EPSS 0.6%CVE-2026-89266HIGHstb_vorbis through 1.22 heap buffer overflow via codebook multiplicandsEPSS 0.6%CVE-2026-60094MEDIUMVinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_serverEPSS 0.6%CVE-2023-26552MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a cliEPSS 0.6%CVE-2023-26554MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a clEPSS 0.6%CVE-2026-54211CRITICALTeamDavid: Buffer Overflow in multiple form data parametersEPSS 0.6%CVE-2024-23123HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.6%CVE-2022-46879HIGHMozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safetyEPSS 0.6%