Falhas do tipo CWE-787

5.179 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-17120MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-54240HIGHlibde265: Pixel accessor signed integer overflow causes heap OOB read/writeEPSS 0.4%CVE-2026-17470MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]EPSS 0.4%CVE-2026-43656HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 andEPSS 0.4%CVE-2024-0023HIGHIn ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could leadEPSS 0.4%CVE-2026-0250MEDIUMGlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or GatewayEPSS 0.4%CVE-2026-20097MEDIUMCisco Integrated Management Controller Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-10678HIGHNULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controllerEPSS 0.4%CVE-2026-10883HIGHType Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a craftEPSS 0.4%CVE-2026-10881CRITICALOut of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escEPSS 0.4%CVE-2022-41143HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-41151HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-41144HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-41147HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-56920HIGHIn s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to EPSS 0.4%CVE-2026-43745MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2026-43703MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS SonoEPSS 0.4%CVE-2024-23150HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2020-35530—In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can beEPSS 0.4%CVE-2022-31606HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a faEPSS 0.4%