Falhas do tipo CWE-787

5.162 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-37419HIGHMultiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2024-34115HIGHZDI-CAN-24054: Adobe Substance 3D Stager SKP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2021-3638—An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while haEPSS 0.4%CVE-2025-23099CRITICALAn issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.EPSS 0.4%CVE-2024-9247HIGHFoxit PDF Reader Annotation Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-0800MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0803MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2023-0802MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2022-42421HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-0801MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, EPSS 0.4%CVE-2023-0804MEDIUMLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a craftedEPSS 0.4%CVE-2025-23097CRITICALAn issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.EPSS 0.4%CVE-2026-12553HIGHHP Web Jetadmin (WJA) - Potential Arbitrary File Read/WriteEPSS 0.4%CVE-2026-54900MEDIUMOj: Negative-Size memcpy in Oj::Parser create_id Attribute HandlingEPSS 0.4%CVE-2022-41842MEDIUMAn issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.EPSS 0.4%CVE-2026-4746CRITICALHeap Buffer Over-Write Vulenrabilty in timeplus-io/protonEPSS 0.4%CVE-2023-33693HIGHA buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML fiEPSS 0.4%CVE-2025-42940HIGHMemory Corruption vulnerability in SAP CommonCryptoLibEPSS 0.4%CVE-2024-23147HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2025-1125HIGHGrub2: fs/hfs: integer overflow may lead to heap based out-of-bounds writeEPSS 0.4%