Falhas do tipo CWE-787

5.182 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-4439HIGHOut of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a EPSS 0.4%CVE-2022-42935HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2022-42938HIGHA malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerabEPSS 0.4%CVE-2023-22240HIGHZDI-CAN-19517: Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-42933HIGHA malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by wrEPSS 0.4%CVE-2026-11728HIGHIBM MQ .NET client is vulnerable to remote code executionEPSS 0.4%CVE-2024-20761HIGHAdobe Animate 2024 BMP File Parsing Out-Of-Bound Write Remote Code execution VulnerabilityEPSS 0.4%CVE-2022-33283HIGHBuffer over-read in WLANEPSS 0.4%CVE-2022-33284HIGHBuffer over-read in WLANEPSS 0.4%CVE-2023-2763HIGHUse-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2024-49513HIGHNot a product | Out-of-bounds Write (CWE-787)EPSS 0.4%CVE-2023-23609HIGHcontiki-ng BLE-L2CAP contains Improper size validation of L2CAP framesEPSS 0.4%CVE-2022-32815HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tEPSS 0.4%CVE-2026-77642HIGHtor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest typeEPSS 0.4%CVE-2022-44650HIGHA memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could alloEPSS 0.4%CVE-2020-14390—A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading EPSS 0.4%CVE-2022-47659HIGHGPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_dataEPSS 0.4%CVE-2022-44649HIGHAn out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could EPSS 0.4%CVE-2022-40363MEDIUMA buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cEPSS 0.4%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.4%