Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-33613MEDIUMaxTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability alEPSS 0.3%CVE-2025-24257HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15EPSS 0.3%CVE-2022-47519HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/micEPSS 0.3%CVE-2018-25252MEDIUMFTP Voyager 16.2.0 Denial of Service via Malformed Site ProfileEPSS 0.3%CVE-2018-9380HIGHIn l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to improper input validation. This could lead to remote escalEPSS 0.3%CVE-2025-58750HIGHrAthena missing bound check in chclif_parse_moveCharSlotEPSS 0.3%CVE-2021-39218MEDIUMOut-of-bounds read/write and invalid free with `externref`s and GC safepoints in WasmtimeEPSS 0.3%CVE-2025-27182HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-27183HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-24800CRITICALA heap-based buffer over-read or buffer overflow in tildearrow/furnaceEPSS 0.3%CVE-2026-18511HIGHIBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets ExtensionEPSS 0.3%CVE-2023-37336HIGHKofax Power PDF TIF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-37334HIGHKofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-13048HIGHAshlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-37337HIGHKofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-13046HIGHAshlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-30775MEDIUMA vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.cEPSS 0.3%CVE-2022-44513HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2022-44512HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-21597HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%