Falhas do tipo CWE-787

5.208 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-53524HIGHFuji Electric Monitouch V-SFT-6 Out-of-bounds WriteEPSS 0.3%CVE-2025-43302MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOSEPSS 0.3%CVE-2022-32925HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be aEPSS 0.3%CVE-2025-30015MEDIUMMemory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)EPSS 0.3%CVE-2022-32813HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 202EPSS 0.3%CVE-2024-45776MEDIUMGrub2: grub-core/gettext: integer overflow leads to heap oob write and read.EPSS 0.3%CVE-2026-102301HIGHOut of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%CVE-2024-45769MEDIUMPcp: pmcd heap corruption through metric pmstore operationsEPSS 0.3%CVE-2022-45491HIGHBuffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (NovembeEPSS 0.3%CVE-2024-44126HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOSEPSS 0.3%CVE-2026-8569HIGHOut of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2021-47640HIGHpowerpc/kasan: Fix early region not updated correctlyEPSS 0.3%CVE-2023-32395—A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS VenturEPSS 0.3%CVE-2024-20083CRITICALIn venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystemEPSS 0.3%CVE-2023-52829HIGHwifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps()EPSS 0.3%CVE-2024-12191HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-12197HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-12192HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-12193HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2022-41873MEDIUMOut-of-bounds read and write in BLE L2CAP moduleEPSS 0.3%