Falhas do tipo CWE-787

5.155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-22268HIGHVMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrEPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2026-16692MEDIUMIBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer ProtocolEPSS 0.5%CVE-2026-20464MEDIUMIn hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a EPSS 0.5%CVE-2026-44254MEDIUMWazuh: Stack Out-of-Bounds Write in remoted Decompression PathEPSS 0.5%CVE-2026-58049HIGHFFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()EPSS 0.5%CVE-2025-32405HIGHAn Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by EPSS 0.5%CVE-2026-64835HIGHFFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio DecoderEPSS 0.5%CVE-2023-20524HIGHAn attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potEPSS 0.5%CVE-2026-53413HIGHZoom Clients - Buffer Over-writeEPSS 0.5%CVE-2022-1785HIGHOut-of-bounds Write in vim/vimEPSS 0.5%CVE-2021-46763HIGHInsufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer poteEPSS 0.5%CVE-2026-12292HIGHIncorrect boundary conditions in the Web Audio componentEPSS 0.5%CVE-2021-47786MEDIUMRedragon Gaming Mouse - 'REDRAGON_MOUSE.sys' Denial of Service (PoC)EPSS 0.5%CVE-2024-38638LOWQTS, QuTS heroEPSS 0.5%CVE-2024-53697LOWQTS, QuTS heroEPSS 0.5%CVE-2023-38118HIGHFoxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-49475HIGHFreeSWITCH: Out-of-bounds memory access in core STUN attribute parsingEPSS 0.5%CVE-2026-73194CRITICALDBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparseEPSS 0.5%CVE-2024-53699LOWQTS, QuTS heroEPSS 0.5%