Falhas do tipo CWE-787

5.179 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2020-35530—In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can beEPSS 0.4%CVE-2026-28979MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2024-11512HIGHIrfanView WBZ Plugin WB1 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-25442HIGHAn issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via paEPSS 0.4%CVE-2026-34971CRITICALWasmtime miscompiled guest heap access enables sandbox escape on aarch64 CraneliftEPSS 0.4%CVE-2023-0972CRITICALBuffer overflow in S0 Decryption on Z/IP GatweayEPSS 0.4%CVE-2022-41310HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2022-42847HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to EPSS 0.4%CVE-2023-48229HIGHOut-of-bounds write in the radio driver for Contiki-NG nRF platformsEPSS 0.4%CVE-2022-42840HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.EPSS 0.4%CVE-2022-36039HIGHOut-of-bounds write when parsing DEX files in RizinEPSS 0.4%CVE-2023-23456MEDIUMUpx: heap-buffer-overflow in packtmt::pack()EPSS 0.4%CVE-2022-42395HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-39500HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-42371HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2018-25154HIGHGNU Barcode 0.99 Buffer Overflow in Code 93 Encoding MechanismEPSS 0.4%CVE-2022-42400HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-42373HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-24188HIGHNVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability miEPSS 0.4%CVE-2022-41149HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%