Falhas do tipo CWE-787

5.177 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-41660HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamceEPSS 0.4%CVE-2023-4041CRITICALSecond Stage Gecko Bootloader GBL Parser Buffer Overrun VulnerabilityEPSS 0.4%CVE-2022-48312CRITICALThe HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiEPSS 0.4%CVE-2026-53702MEDIUMGstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period sei parserEPSS 0.4%CVE-2022-41309HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2018-9341CRITICALIn impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbiEPSS 0.4%CVE-2026-9872CRITICALOut of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox esEPSS 0.4%CVE-2022-46697HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to EPSS 0.4%CVE-2024-27907HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds writeEPSS 0.4%CVE-2022-41185—Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received fEPSS 0.4%CVE-2024-9114HIGHFastStone Image Viewer GIF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-41844MEDIUMAn issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability thaEPSS 0.4%CVE-2023-34269HIGHFatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-93015HIGHBlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds WriteEPSS 0.4%CVE-2022-42944HIGHA malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by reaEPSS 0.4%CVE-2022-42936HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2023-34265HIGHFatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-34267HIGHFatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-34264HIGHFatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-42942HIGHA malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by reaEPSS 0.4%