Falhas do tipo CWE-787

5.205 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-47134HIGHOut-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 anEPSS 0.3%CVE-2022-43152MEDIUMtsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitStream.h.EPSS 0.3%CVE-2024-20044MEDIUMIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System eEPSS 0.3%CVE-2024-20042MEDIUMIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System eEPSS 0.3%CVE-2022-43148MEDIUMrtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h.EPSS 0.3%CVE-2023-3611HIGHOut-of-bounds write in Linux kernel's net/sched: sch_qfq componentEPSS 0.3%CVE-2024-20028MEDIUMIn da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execuEPSS 0.3%CVE-2022-44079MEDIUMpycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBaEPSS 0.3%CVE-2025-52952HIGHJunos OS: MX Series with MPC-BUILTIN, MPC 1 through MPC 9: Receipt and processing of a malformed packet causes one or more FPCs to crashEPSS 0.3%CVE-2024-39381HIGHAfter Effects | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2024-0090HIGHCVEEPSS 0.3%CVE-2025-43224HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15EPSS 0.3%CVE-2024-52573HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2021-34857HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.3%CVE-2024-52569HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2026-84969MEDIUMHeap overflow via truncated base64 encoding of binary fields in length-limited JSON outputEPSS 0.3%CVE-2021-27242HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker muEPSS 0.3%CVE-2023-32276HIGHStack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may leadEPSS 0.3%CVE-2024-4081HIGHMemory Corruption Due to Improper Length Check in NI LabVIEWEPSS 0.3%CVE-2024-45774MEDIUMGrub2: reader/jpeg: heap oob write during jpeg parsingEPSS 0.3%