Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2010-3843—The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this EPSS 0.3%CVE-2025-32403MEDIUMAn Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the libraryEPSS 0.3%CVE-2025-32404MEDIUMAn Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the libraryEPSS 0.3%CVE-2022-43653HIGHBentley View SKP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-12768HIGHFactoryTalk® Historian Machine Edition - Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2024-23148HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2022-22063HIGHMemory corruption in CoreEPSS 0.3%CVE-2026-12633HIGHOut-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router AdvertisementEPSS 0.3%CVE-2023-7298MEDIUMOut-of-Bounds Write Vulnerability in in Autodesk Desktop SoftwareEPSS 0.3%CVE-2022-41283HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamcenEPSS 0.3%CVE-2026-32706HIGHPX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packetEPSS 0.3%CVE-2025-48499MEDIUMOut-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (EPSS 0.3%CVE-2025-14332HIGHMemory safety bugs fixed in Firefox 146 and Thunderbird 146EPSS 0.3%CVE-2023-42908HIGHMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliEPSS 0.3%CVE-2023-38683HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.5), Teamcenter Visualization V13.2 (All versions < V13.2.0.14), TeamcenEPSS 0.3%CVE-2024-9735HIGHTungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-91711HIGHOut of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the EPSS 0.3%CVE-2022-45332HIGHLibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.EPSS 0.3%CVE-2024-9737HIGHTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-39118MEDIUMMommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up.EPSS 0.3%