Falhas do tipo CWE-787

5.153 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-45496HIGHBuffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (NovembEPSS 0.6%CVE-2026-36355HIGHThe rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access controEPSS 0.6%CVE-2026-32740HIGHlibheif: Heap-Buffer-Overflow Write in Grid Tile Chroma CompositingEPSS 0.6%CVE-2025-27598HIGHOut-of-bounds Write in SixLabors ImageSharpEPSS 0.6%CVE-2022-38980CRITICALThe HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of thiEPSS 0.6%CVE-2026-26955HIGHFreeRDP has Out-of-bounds WriteEPSS 0.6%CVE-2024-1557HIGHMemory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2026-44049HIGHOut-of-bounds write in convert_charset() null terminationEPSS 0.6%CVE-2026-44062HIGHMissing o_len bounds check in pull_charset_flags()EPSS 0.6%CVE-2024-27228CRITICALthere is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional executionEPSS 0.6%CVE-2023-3633HIGHOut of Bounds Memory Corruption Issue in CEVA EngineEPSS 0.6%CVE-2022-39803—Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file receiveEPSS 0.6%CVE-2022-39804—Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Part (.sldprt, CoreCadTranslator.exe) file received frEPSS 0.6%CVE-2022-46690HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13EPSS 0.6%CVE-2024-23124HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.6%CVE-2026-40492CRITICALSAIL has heap buffer overflow in XWD decoder — bits_per_pixel vs pixmap_depth type confusion in byte-swapEPSS 0.6%CVE-2022-41307HIGHA maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by reEPSS 0.6%CVE-2026-71254CRITICALnanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()EPSS 0.6%CVE-2026-40494CRITICALSAIL has heap buffer overflow in TGA RLE decoder — raw packet path missing bounds checkEPSS 0.6%CVE-2026-59147CRITICALData::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_findEPSS 0.6%