Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-41202HIGHDue to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrustedEPSS 0.6%CVE-2022-41198—Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sourceEPSS 0.6%CVE-2022-41200—Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic (.svg, svg.x3d) file received from untrusEPSS 0.6%CVE-2025-25744CRITICALD-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamEPSS 0.6%CVE-2025-25746CRITICALD-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSeEPSS 0.6%CVE-2023-1906MEDIUMA heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An EPSS 0.6%CVE-2022-32843HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS BiEPSS 0.6%CVE-2026-5317MEDIUMNothings stb stb_vorbis.c start_decoder out-of-bounds writeEPSS 0.6%CVE-2016-8617LOWThe base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at leastEPSS 0.6%CVE-2026-85091HIGHzlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacateEPSS 0.6%CVE-2026-86098HIGHntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escapeEPSS 0.6%CVE-2025-1016CRITICALMemory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7EPSS 0.6%CVE-2024-23608HIGHOut of Bounds Write Due to Missing Bounds Check in LabVIEWEPSS 0.6%CVE-2024-23610HIGHOut of Bounds Write Due to Missing Bounds Check in LabVIEWEPSS 0.6%CVE-2026-5734HIGHMemory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.6%CVE-2026-58184HIGHApache Traffic Server: header_rewrite plugin cookie handling can corrupt memoryEPSS 0.6%CVE-2022-23973HIGHASUS RT-AX56U - Stack overflewEPSS 0.6%CVE-2022-41196—Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sourcesEPSS 0.6%CVE-2022-25596HIGHASUS RT-AC86U - Heap-based buffer overflowEPSS 0.6%CVE-2026-17436HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%