Falhas do tipo CWE-787

5.208 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2024-9733HIGHTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-43588HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-17252HIGHUnauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management InterfaceEPSS 0.3%CVE-2026-94054HIGHExim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.EPSS 0.3%CVE-2025-43505HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously craftEPSS 0.3%CVE-2025-2020HIGHAshlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-54509HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, mEPSS 0.3%CVE-2025-21121HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2023-21489HIGHHeap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.EPSS 0.3%CVE-2022-32860HIGHAn out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, mEPSS 0.3%CVE-2025-43581HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-72897HIGHOut-of-Bounds Access After SSL_set_SSL_CTX() During a HandshakeEPSS 0.3%CVE-2026-12052MEDIUMOut-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the responseEPSS 0.3%CVE-2025-71004MEDIUMA segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2022-48423HIGHIn the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.EPSS 0.3%CVE-2026-8314HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%CVE-2026-8312HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%CVE-2021-0153HIGHOut-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of priviEPSS 0.3%CVE-2026-8085HIGHRockwell Automation Arena® - Memory Corruption VulnerabilityEPSS 0.3%