Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-27340HIGHPDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-27341HIGHPDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-32160HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-32161HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-32159HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-27339HIGHPDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-46866MEDIUMIn International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access arEPSS 0.6%CVE-2023-49351CRITICALA stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite oEPSS 0.6%CVE-2026-95508HIGHLibslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtuEPSS 0.6%CVE-2024-42952HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerabEPSS 0.6%CVE-2025-27105LOWAugAssign evaluation order causing OOB write within the object in VyperEPSS 0.6%CVE-2024-36243HIGHArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.6%CVE-2026-62349HIGHTDengine: Off-by-One Buffer OverflowEPSS 0.6%CVE-2024-36260HIGHArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.6%CVE-2023-4020CRITICALUnvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memoryEPSS 0.6%CVE-2026-28693HIGHImageMagick has an integer overflow in DIB coder can result in out of bounds read or writeEPSS 0.6%CVE-2018-9411HIGHIn decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitraEPSS 0.6%CVE-2026-81625HIGHStack buffer overflow in Greenbone OS and openvas-scannerEPSS 0.6%CVE-2026-34588HIGHOpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/WriteEPSS 0.6%CVE-2025-57709LOWQsync CentralEPSS 0.6%