Falhas do tipo CWE-787

5.155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-62434MEDIUMPoD: Don't try to reclaim special pagesEPSS 0.5%CVE-2026-10849HIGHHeap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bodyEPSS 0.5%CVE-2023-42753HIGHKernel: netfilter: potential slab-out-of-bound access due to integer underflowEPSS 0.5%CVE-2022-22088CRITICALInteger Overflow to Buffer Overflow in Bluetooth HOSTEPSS 0.5%CVE-2024-9121HIGHInappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds meEPSS 0.5%CVE-2025-20725HIGHIn ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, ifEPSS 0.5%CVE-2022-46885HIGHMozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of theEPSS 0.5%CVE-2026-6679HIGHDTLS 1.3 ACK serialization heap buffer overflow via integer truncationEPSS 0.5%CVE-2024-20501HIGHMultiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could alEPSS 0.5%CVE-2024-20499HIGHMultiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could alEPSS 0.5%CVE-2023-0137HIGHHeap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to instaEPSS 0.5%CVE-2023-0129HIGHHeap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a maliciEPSS 0.5%CVE-2026-93451MEDIUMsnappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methodsEPSS 0.5%CVE-2026-19642MEDIUMOut-of-bounds write in the Base64 decoder in Amazon aws-sdk-cppEPSS 0.5%CVE-2026-71263CRITICALFreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool()EPSS 0.5%CVE-2024-22254HIGHOut-of-bounds write vulnerabilityEPSS 0.5%CVE-2024-36114HIGHDecompressors can crash the JVM and leak memory content in AircompressorEPSS 0.5%CVE-2026-17636HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.5%CVE-2024-20357MEDIUMA vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an EPSS 0.5%CVE-2025-41649HIGHWeidmueller: Out-of-Bounds Write Vulnerability in Industrial Ethernet SwitchesEPSS 0.5%