Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-48626HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VEPSS 0.3%CVE-2023-48625HIGHAdobe Substance 3D Sampler v4.2.1Build3527 OOBW Vulnerability VIEPSS 0.3%CVE-2023-47041HIGHZDI-CAN-21697: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-33234HIGHMemory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon ConsumEPSS 0.3%CVE-2023-31908HIGHJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component ecma_builtin_typedarray_prototype_sort.EPSS 0.3%CVE-2023-21582HIGHZDI-CAN-18255: Adobe Digital Editions PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-0677MEDIUMGrub2: ufs: integer overflow may lead to heap based out-of-bounds write when handling symlinksEPSS 0.3%CVE-2026-24793CRITICALA heap-based buffer over-read or buffer overflow vulnerability in azerothcore/azerothcore-wotlkEPSS 0.3%CVE-2026-90949HIGHGimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatchEPSS 0.3%CVE-2026-42046HIGHlibcaca: Heap OOB write in canvas import functions caused by int overflowEPSS 0.3%CVE-2023-31907HIGHJerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerry-core/parser/js/js-EPSS 0.3%CVE-2022-35080MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.EPSS 0.3%CVE-2026-16825MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-58099HIGHvmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frameEPSS 0.3%CVE-2022-43281HIGHwasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() EPSS 0.3%CVE-2022-35081MEDIUMSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.EPSS 0.3%CVE-2024-7137MEDIUMDenial of Service in Silicon Labs RS9116 Bluetooth SDKEPSS 0.3%CVE-2025-5272HIGHMemory safety bugs fixed in Firefox 139 and Thunderbird 139EPSS 0.3%CVE-2024-12178HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2026-31789MEDIUMHeap Buffer Overflow in Hexadecimal ConversionEPSS 0.3%