Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-31789MEDIUMHeap Buffer Overflow in Hexadecimal ConversionEPSS 0.3%CVE-2024-32905CRITICALIn circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to reEPSS 0.3%CVE-2022-47665HIGHLibde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)EPSS 0.3%CVE-2026-10907HIGHOut of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a EPSS 0.3%CVE-2024-30296HIGHWhen Animate parses FLA files, there is an out-of-bounds write vulnerability at animate+0x123df28EPSS 0.3%CVE-2024-30297HIGHWhen Adobe Animate parses FLA files, there is a heap out-of-bounds write vulnerability at Animate.exe+0x125D391EPSS 0.3%CVE-2026-10892CRITICALOut of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2024-7139MEDIUMDenial of Service in Silicon Labs RS9116 Bluetooth SDKEPSS 0.3%CVE-2026-19173HIGHOut of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2022-42820HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An EPSS 0.3%CVE-2024-47443HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-44321MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from LexScanGetTokeEPSS 0.3%CVE-2026-24832CRITICALOut-of-bounds write in ixray-1.6-stcopEPSS 0.3%CVE-2021-40367HIGHA vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied dataEPSS 0.3%CVE-2024-47441HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-29950MEDIUMswfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.cEPSS 0.3%CVE-2024-47442HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2021-42028HIGHA vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied dataEPSS 0.3%CVE-2026-5068HIGHbt: l2cap le coc: remote oob write via seg counter stored in net_buf user_dataEPSS 0.3%CVE-2022-44314MEDIUMPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExprEPSS 0.3%