Falhas do tipo CWE-787

5.154 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-41177—Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file EPSS 0.5%CVE-2022-41167—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrustedEPSS 0.5%CVE-2022-41172—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrustedEPSS 0.5%CVE-2022-41170—Due to lack of proper memory management, when a victim opens a manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrEPSS 0.5%CVE-2022-41179—Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from unEPSS 0.5%CVE-2026-78161MEDIUMwarmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds writeEPSS 0.5%CVE-2023-21054HIGHIn EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lEPSS 0.5%CVE-2024-33008MEDIUMMemory Corruption vulnerability in SAP Replication ServerEPSS 0.5%CVE-2022-28668HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.9.2. User interaEPSS 0.5%CVE-2022-37234HIGHNetgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary iEPSS 0.5%CVE-2020-1751MEDIUMAn out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtraceEPSS 0.5%CVE-2024-5844HIGHHeap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read EPSS 0.5%CVE-2026-58154CRITICALApache Traffic Server: Memory-safety errors in MIME and header parsingEPSS 0.5%CVE-2022-39805—Due to lack of proper memory management, when a victim opens a manipulated Computer Graphics Metafile (.cgm, CgmTranslator.exe) file receiveEPSS 0.5%CVE-2024-56406HIGHPerl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytesEPSS 0.5%CVE-2026-62817HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-51597HIGHKofax Power PDF U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-6786HIGHMemory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2026-55827HIGHFreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decodeEPSS 0.5%CVE-2026-6785HIGHMemory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%