Falhas do tipo CWE-787

5.182 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-70354HIGH.NET Core Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-33636HIGHLIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64EPSS 0.4%CVE-2024-49551HIGHMedia Encoder | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2026-24797MEDIUMAn out of bounds write due to a missing bounds check in neka-nat/cupochEPSS 0.4%CVE-2023-26923HIGHMusescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additionEPSS 0.4%CVE-2026-5589MEDIUMOut-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.EPSS 0.4%CVE-2024-49553HIGHMedia Encoder | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2023-48630HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability IEPSS 0.4%CVE-2026-18269MEDIUMKenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution VulnerabilityEPSS 0.4%CVE-2024-22913HIGHA heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code executiEPSS 0.4%CVE-2023-50671HIGHIn exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected addEPSS 0.4%CVE-2022-42380HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-39386HIGHZDI-CAN-24057: Adobe Bridge AVI FIle Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-8669MEDIUMImager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF filesEPSS 0.4%CVE-2022-33265HIGHInformation exposure in Powerline Communication FirmwareEPSS 0.4%CVE-2022-42381HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-25423HIGHAn issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.EPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2022-42410HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2022-42382HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%