Falhas do tipo CWE-787

5.172 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-16847HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2022-33255HIGHBuffer over-read in Bluetooth HOSTEPSS 0.4%CVE-2026-16841HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2022-35098MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxEPSS 0.4%CVE-2025-68473NONEESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result HandlingEPSS 0.4%CVE-2026-5873HIGHOut of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2024-23157HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2026-14739CRITICALDBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholdersEPSS 0.4%CVE-2026-79240HIGHOut of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrarEPSS 0.4%CVE-2022-35093MEDIUMSWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.EPSS 0.4%CVE-2026-79127HIGHOut of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandboxEPSS 0.4%CVE-2022-45494HIGHBuffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (NovembEPSS 0.4%CVE-2022-35094MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.EPSS 0.4%CVE-2026-14395HIGHOut of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via aEPSS 0.4%CVE-2026-7957HIGHOut of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer EPSS 0.4%CVE-2024-23156HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2026-9896HIGHOut of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%CVE-2022-35099MEDIUMSWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.EPSS 0.4%CVE-2026-9879HIGHOut of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTMLEPSS 0.4%CVE-2026-19162HIGHOut of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%