Falhas do tipo CWE-787

5.182 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-23107HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.EPSS 0.3%CVE-2025-23103HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.EPSS 0.3%CVE-2025-0144LOWZoom Workplace Apps - Out-of-bounds WriteEPSS 0.3%CVE-2026-27816MEDIUMEVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE stateEPSS 0.3%CVE-2022-39394LOWwasmtime_trap_code C API function has out of bounds write vulnerabilityEPSS 0.3%CVE-2026-27815MEDIUMEVerest: ISO15118 session_setup payment options overflow can corrupt EVSE stateEPSS 0.3%CVE-2024-12835HIGHDelta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-41595HIGHDrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of mEPSS 0.3%CVE-2026-24811CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inffast.cEPSS 0.3%CVE-2025-22377MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.3%CVE-2026-17207MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.3%CVE-2024-1696HIGHSantesoft Sante FFT Imaging Out-of-bounds WriteEPSS 0.3%CVE-2026-20433HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.3%CVE-2023-51395HIGHZ-Wave S0 Decryption Vulnerability in End DevicesEPSS 0.3%CVE-2026-86869MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden GateEPSS 0.3%CVE-2022-33185HIGHSeveral commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. AutheEPSS 0.3%CVE-2026-2923HIGHGStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-43750MEDIUMdrivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitoEPSS 0.3%CVE-2026-18693HIGHOut-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory DisclosureEPSS 0.3%CVE-2026-12522HIGHStack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fieldsEPSS 0.3%