Falhas do tipo CWE-787

5.202 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-34823MEDIUMfdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.EPSS 0.3%CVE-2025-27374MEDIUMAn issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 10EPSS 0.3%CVE-2026-65703HIGHFFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video DecoderEPSS 0.3%CVE-2024-39384HIGHPremiere Pro | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-20782HIGHAdobe Indesign WMF File Parsing Out Of Bound WriteEPSS 0.3%CVE-2023-34970MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.3%CVE-2025-32008HIGHOut-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a deEPSS 0.3%CVE-2023-25860HIGHAdobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-26373HIGHAdobe Dimension has an arbitrary address write vulnerability when parsing USDZ filesEPSS 0.3%CVE-2023-25870HIGHAdobe Substance 3D Stager SVG File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-22230HIGHAdobe Bridge Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-30272HIGHAdobe Illustrator 2024 GIF file parsing Out-Of-Bound Write remote code execution vulnerabiityEPSS 0.3%CVE-2023-3024MEDIUMBluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory accessEPSS 0.3%CVE-2023-25866HIGHAdobe Substance 3D Stager OBJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-25861HIGHAdobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-21589HIGHAdobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-30271HIGHAdobe Illustrator 2023 CC 27.7 Memory Corruption Out-Of-Bounds-Write Vulnerability III.EPSS 0.3%CVE-2023-34319HIGHLinux: buffer overrun in netback due to unusual packetEPSS 0.3%CVE-2024-27873MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 andEPSS 0.3%CVE-2026-12520MEDIUMStack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlersEPSS 0.3%