Falhas do tipo CWE-787

5.171 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-29308HIGH[FG-VD-23-009] Adobe InDesign 2023 Arbitrary Code Execution Vulnerability NotificationEPSS 0.4%CVE-2022-41306HIGHA maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write accEPSS 0.4%CVE-2024-27342HIGHKofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-27339HIGHKofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-50410CRITICALNFSD: Protect against send buffer overflow in NFSv2 READEPSS 0.4%CVE-2024-37000HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2026-22852MEDIUMFreeRDP has a heap-buffer-overflow in audin_process_formatsEPSS 0.4%CVE-2019-25564MEDIUMPCHelpWareV2 1.0.0.5 Denial of Service via Group FieldEPSS 0.4%CVE-2024-53000HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2024-53958HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2024-11559HIGHIrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-41431HIGHTMM VulnerabilityEPSS 0.4%CVE-2026-22184MEDIUMzlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()EPSS 0.4%CVE-2024-53001HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2026-10941HIGHOut of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2024-53002HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2026-0899HIGHOut of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruptionEPSS 0.4%CVE-2025-1050HIGHSonos Era 300 Out-of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-18095HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2023-52369CRITICALStack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%