Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-12363MEDIUMOut-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0EPSS 0.2%CVE-2022-35407HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SeEPSS 0.2%CVE-2024-41928HIGHbhyve(8) privileged guest escape via TPM device passthroughEPSS 0.2%CVE-2024-54517HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOSEPSS 0.2%CVE-2022-43448HIGHOut-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker to obtain the inforEPSS 0.2%CVE-2024-11156HIGHRockwell Automation Arena® Out of Bounds Write VulnerabilityEPSS 0.2%CVE-2025-49563HIGHIllustrator | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-27970HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be ablEPSS 0.2%CVE-2025-54206HIGHInDesign Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-103109HIGHPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remEPSS 0.2%CVE-2025-1254HIGHOut-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers.EPSS 0.2%CVE-2025-30304HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-76880HIGHOut-of-bounds Write in WiresharkEPSS 0.2%CVE-2024-20043MEDIUMIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System eEPSS 0.2%CVE-2025-30297HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-31601MEDIUMNVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-boEPSS 0.2%CVE-2025-49570HIGHPhotoshop Desktop | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-24451HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-31858HIGHOut-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enEPSS 0.2%CVE-2025-24440HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%