Falhas do tipo CWE-787

5.158 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-62818CRITICALAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.5%CVE-2026-79188CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-79131CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandboxEPSS 0.5%CVE-2026-79138CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-5733HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.5%CVE-2026-79189CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-85050CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46274HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.EPSS 0.5%CVE-2026-87621CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2026-79043CRITICALOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2026-79019CRITICALOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.5%CVE-2024-46264HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.EPSS 0.5%CVE-2026-87438CRITICALOut of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outsiEPSS 0.5%CVE-2024-46267HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.EPSS 0.5%CVE-2024-46263HIGHcute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.EPSS 0.5%CVE-2026-87638CRITICALOut of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.5%CVE-2024-46276HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.EPSS 0.5%CVE-2024-46259HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.EPSS 0.5%CVE-2023-38072HIGHA vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), TeamcenEPSS 0.5%CVE-2026-5735HIGHMemory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.5%