Falhas do tipo CWE-787

5.209 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2018-25211HIGHAllok Video Splitter 3.1.1217 Buffer Overflow via License NameEPSS 0.3%CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2024-35976HIGHxsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RINGEPSS 0.3%CVE-2024-56615HIGHbpf: fix OOB devmap writes when deleting elementsEPSS 0.3%CVE-2024-20148CRITICALIn wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) codeEPSS 0.3%CVE-2020-9695HIGHAcrobat Reader | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2025-10899HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-10900HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-54210HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2021-33124MEDIUMOut-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aesEPSS 0.3%CVE-2025-10888HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2024-43097HIGHIn resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation EPSS 0.3%CVE-2025-10898HIGHMODEL File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.3%CVE-2025-54213HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.3%CVE-2026-68967HIGHOut-of-bounds Write in Bendix EC80 Brake ECUEPSS 0.3%CVE-2026-35195MEDIUMWasmtime has an out-of-bounds write or crash when transcoding component model stringsEPSS 0.3%CVE-2019-25631HIGHAIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2019-25633HIGHAIDA64 Extreme 5.99.4900 SEH Buffer Overflow via EggHunterEPSS 0.3%CVE-2024-23234HIGHAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, EPSS 0.3%CVE-2026-34682HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.3%