Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-49544HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-42926HIGHMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliEPSS 0.3%CVE-2026-40919MEDIUMGimp: gimp: denial of service via specially crafted seattle filmworks fileEPSS 0.3%CVE-2024-52994HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-81738LOWOpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEPSS 0.3%CVE-2023-37766—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/lEPSS 0.3%CVE-2022-41304HIGHAn Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK 2020 version and prior may lead to code execution through maliciously crafted FBX fEPSS 0.3%CVE-2023-37765—GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpEPSS 0.3%CVE-2025-20633HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) cEPSS 0.3%CVE-2025-52513HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds EPSS 0.3%CVE-2024-49538HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-31910HIGHJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at /jerrEPSS 0.3%CVE-2026-4450HIGHOut of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.3%CVE-2026-84588MEDIUMA memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciouslyEPSS 0.3%CVE-2026-4440HIGHOut of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2026-4459HIGHOut of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corrEPSS 0.3%CVE-2024-11579HIGHLuxion KeyShot OBJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-48639HIGHAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IEPSS 0.3%CVE-2023-48625HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VIEPSS 0.3%CVE-2023-48626HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VEPSS 0.3%