Falhas do tipo CWE-787

5.155 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-46323CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46319CRITICALFingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bouEPSS 0.5%CVE-2022-46325CRITICALSome smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptionEPSS 0.5%CVE-2022-46324CRITICALSome smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptioEPSS 0.5%CVE-2021-47719HIGHCNC_Ctrl DllUnregisterServer f5501 Access ViolationEPSS 0.5%CVE-2023-51569HIGHKofax Power PDF BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-21927CRITICALnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()EPSS 0.5%CVE-2026-29774MEDIUMFreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRectsEPSS 0.5%CVE-2021-47705HIGHCNC_Ctrl DllUnregisterServer Access ViolationEPSS 0.5%CVE-2020-21723—A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remoteEPSS 0.5%CVE-2026-10879CRITICALDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersEPSS 0.5%CVE-2026-49840CRITICALFreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingEPSS 0.5%CVE-2026-5187LOWHeap Out-of-Bounds Write in DecodeObjectId() in wolfSSLEPSS 0.5%CVE-2024-41879HIGHRE: New Edge T5 MSRC Case [DCMSFT-1294]EPSS 0.5%CVE-2025-29031CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.EPSS 0.5%CVE-2025-29030CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.EPSS 0.5%CVE-2025-41766HIGHStack buffer overflow on parsing web requestEPSS 0.5%CVE-2025-29029CRITICALTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.EPSS 0.5%CVE-2025-25372HIGHNASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management ModuleEPSS 0.5%CVE-2026-2807CRITICALMemory safety bugs fixed in Firefox 148 and Thunderbird 148EPSS 0.5%