Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-22056HIGHnetfilter: nft_tunnel: fix geneve_opt type confusion additionEPSS 0.3%CVE-2023-47057HIGHZDI-CAN-21764: Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-31696HIGHVMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local acceEPSS 0.3%CVE-2023-26328HIGHZDI-CAN-20212: Adobe Dimension USD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-45587MEDIUMStack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.EPSS 0.3%CVE-2026-7354HIGHOut of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2022-41686MEDIUMOut-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The proc ...EPSS 0.3%CVE-2023-34305HIGHAshlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-47314HIGHOut-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5daEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2022-43040HIGHGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedEPSS 0.3%CVE-2024-24922HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2022-28667MEDIUMOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially eEPSS 0.3%CVE-2024-24924HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2024-24920HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds writeEPSS 0.3%CVE-2023-47046MEDIUMZDI-CAN-21684: Adobe Audition MP4 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-23795HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2023-47063HIGHAdobe Illustrator 2023 CC 27.7 Memory Corruption Out-Of-Bounds-Write Vulnerability IV.EPSS 0.3%CVE-2023-31906HIGHJerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jEPSS 0.3%CVE-2022-45586MEDIUMStack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.EPSS 0.3%