Falhas do tipo CWE-787

5.155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-38638LOWQTS, QuTS heroEPSS 0.5%CVE-2024-43091CRITICALIn filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code EPSS 0.5%CVE-2019-25478HIGHGetGo Download Manager 6.2.2.3300 Buffer Overflow DoSEPSS 0.5%CVE-2026-59087HIGHGimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocationEPSS 0.5%CVE-2023-27909HIGHAn Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX EPSS 0.5%CVE-2023-3090HIGHOut-of-bounds write in Linux kernel's ipvlan network driverEPSS 0.5%CVE-2024-5513HIGHKofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-32827MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able EPSS 0.5%CVE-2026-34987CRITICALWasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessEPSS 0.5%CVE-2024-24957HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2023-20954CRITICALIn SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code eEPSS 0.5%CVE-2024-24955HIGHSeveral out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3EPSS 0.5%CVE-2023-20951CRITICALIn gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remoEPSS 0.5%CVE-2023-21057CRITICALIn ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to EPSS 0.5%CVE-2025-60338HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerabiliEPSS 0.5%CVE-2026-26459HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when prEPSS 0.5%CVE-2026-55233HIGHOpenResty: Buffer overflow when writing PROXY protocol v2 header to upstreamEPSS 0.5%CVE-2023-2124—An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with EPSS 0.5%CVE-2022-46326CRITICALSome smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptioEPSS 0.5%CVE-2026-66041HIGHFFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc FilterEPSS 0.5%