Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-11928CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2023-21597HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-44245HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, mEPSS 0.3%CVE-2023-30414MEDIUMJerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.EPSS 0.3%CVE-2022-44513HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-39394HIGHAdobe Indesign 2024 PDF File Parsing Out Of Bound Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21595HIGHAdobe InCopy Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-32866HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS MontereEPSS 0.3%CVE-2026-13873MEDIUMOut of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2021-39822HIGHAdobe InDesign BMP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-57807LOWImageMagick BlobStream Forward-Seek Under-AllocationEPSS 0.3%CVE-2022-31610HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabiEPSS 0.3%CVE-2025-1276HIGHDWG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2026-6325LOWOut-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listEPSS 0.3%CVE-2026-20432HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.3%CVE-2022-3219LOWGnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressEPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%CVE-2023-34823MEDIUMfdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.EPSS 0.3%CVE-2025-27374MEDIUMAn issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 10EPSS 0.3%CVE-2026-24817HIGHA potential heap-buffer overflow in praydog/UEVREPSS 0.3%