Falhas do tipo CWE-787

5.158 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.5%CVE-2026-40691HIGHPacket of death for DNSCrypt over TCPEPSS 0.5%CVE-2026-88407HIGHAn out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers EPSS 0.5%CVE-2026-15057HIGHIBM WebSphere Application Server Liberty is affected by a denial of service vulnerabilityEPSS 0.5%CVE-2026-77544HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%CVE-2026-26284MEDIUMImageMagick has heap overflow in pcd decoder that leads to out of bounds read.EPSS 0.5%CVE-2026-77555HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%CVE-2026-29078HIGHInteger Underflow in Lexbor ISO‑2022‑JP EncoderEPSS 0.5%CVE-2026-29775MEDIUMFreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheIdEPSS 0.5%CVE-2026-95862HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%CVE-2025-43373HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AEPSS 0.5%CVE-2025-14178MEDIUMHeap buffer overflow in array_merge()EPSS 0.5%CVE-2024-0446HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2026-43907HIGHOpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR)EPSS 0.5%CVE-2026-6753HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2025-68381MEDIUMPacketbeat Improper Bounds CheckEPSS 0.5%CVE-2026-8973HIGHMemory safety bugs fixed in Firefox 151EPSS 0.5%CVE-2021-3697—A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a succeEPSS 0.5%CVE-2026-7323HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2020-37011HIGHGnome Fonts Viewer 3.34.0 Heap CorruptionEPSS 0.5%