Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-53855HIGHAn out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadeEPSS 0.3%CVE-2025-15359CRITICALDVP-12SE11T - Out-of-bound memory write VulnerabilityEPSS 0.3%CVE-2022-43039MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at EPSS 0.3%CVE-2023-40152HIGHFuji Electric Tellus Lite V-Simulator Out-of-bounds WriteEPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2022-35090MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.EPSS 0.3%CVE-2024-43760HIGHPhotoshop Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-44312MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called froEPSS 0.3%CVE-2024-53842CRITICALIn cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead toEPSS 0.3%CVE-2024-20103CRITICALIn wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with noEPSS 0.3%CVE-2026-42910HIGHWindows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-22911HIGHA stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.EPSS 0.3%CVE-2023-27754MEDIUMvox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attackeEPSS 0.3%CVE-2024-22955HIGHswftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576EPSS 0.3%CVE-2026-71345HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-20100CRITICALIn wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no aEPSS 0.3%CVE-2023-37174—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedumEPSS 0.3%CVE-2022-47518HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wiEPSS 0.3%CVE-2024-37022HIGHFuji Electric Tellus Lite V-Simulator Out-of-bounds WriteEPSS 0.3%CVE-2024-52994HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%