Falhas do tipo CWE-787

5.154 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-78011HIGHFireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS)EPSS 0.5%CVE-2022-23561HIGHOut of bounds write in TFLiteEPSS 0.5%CVE-2026-2940MEDIUMZaher1307 tiny_web_server URL tiny.c out-of-bounds writeEPSS 0.5%CVE-2024-24956HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2018-16847HIGHAn OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvEPSS 0.5%CVE-2024-24958HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2026-78010HIGHFireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of ServiceEPSS 0.5%CVE-2024-24954HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2024-24959HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2025-20681CRITICALIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.5%CVE-2025-42877HIGHMemory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content ServerEPSS 0.5%CVE-2026-70456HIGHrsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()EPSS 0.5%CVE-2026-20657MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOEPSS 0.5%CVE-2026-8092HIGHMemory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2EPSS 0.5%CVE-2026-70458HIGHrsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED HandlingEPSS 0.5%CVE-2025-20684CRITICALIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.5%CVE-2026-82071HIGHInsufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteEPSS 0.5%CVE-2022-41168—Due to lack of proper memory management, when a victim opens a manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from unEPSS 0.5%CVE-2022-41177—Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file EPSS 0.5%CVE-2022-41172—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrustedEPSS 0.5%