Falhas do tipo CWE-787

5.180 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-41149HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-35092MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.EPSS 0.4%CVE-2022-36041HIGHRizin Out-of-bounds Write vulnerability in Mach-O binary pluginEPSS 0.4%CVE-2022-41148HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-71255HIGHnanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()EPSS 0.4%CVE-2022-36040HIGHRizin Out-of-bounds Write vulnerability in pyc/marshal.cEPSS 0.4%CVE-2022-36044HIGHRizin Out-of-bounds Write vulnerability in Lua binary pluginEPSS 0.4%CVE-2025-23328HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write through aEPSS 0.4%CVE-2026-11933HIGHPost-authentication use-after-free in server-side JavaScript BSON-to-array conversionEPSS 0.4%CVE-2025-47206HIGHFile Station 5EPSS 0.4%CVE-2024-27836HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. Processing aEPSS 0.4%CVE-2026-13033HIGHOut of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitraryEPSS 0.4%CVE-2024-8830HIGHPDF-XChange Editor XPS File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-30273HIGHQTS, QuTS heroEPSS 0.4%CVE-2022-33285HIGHBuffer over-read in WLANEPSS 0.4%CVE-2023-39502HIGHPDF-XChange Editor OXPS File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-39497HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-39499HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-66590HIGHOut-of-bounds Write vulnerability in AzeoTech DAQFactoryEPSS 0.4%CVE-2022-33286HIGHBuffer over-read in WLANEPSS 0.4%