Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-45320MEDIUMOut-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw EPSS 0.2%CVE-2025-24451HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-31858HIGHOut-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enEPSS 0.2%CVE-2026-20403MEDIUMIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connectedEPSS 0.2%CVE-2026-24829MEDIUMOut-of-bounds write in is-EngineEPSS 0.2%CVE-2024-25578HIGHMicroDicom DICOM Viewer Out-of-Bounds WriteEPSS 0.2%CVE-2021-33137HIGHOut-of-bounds write in the Intel(R) Kernelflinger project may allow an authenticated user to potentially enable escalation of privilege via EPSS 0.2%CVE-2026-1418MEDIUMGPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds writeEPSS 0.2%CVE-2022-3379HIGH Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FEPSS 0.2%CVE-2024-53106HIGHima: fix buffer overrun in ima_eventdigest_init_commonEPSS 0.2%CVE-2023-0124HIGHCVE-2023-0124EPSS 0.2%CVE-2016-20044HIGHPInfo 0.6.9-5.1 Local Buffer Overflow via -m ParameterEPSS 0.2%CVE-2025-50054MEDIUMBuffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too laEPSS 0.2%CVE-2021-29571MEDIUMMemory corruption in `DrawBoundingBoxesV2`EPSS 0.2%CVE-2023-38681HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2022-48330HIGHA Huawei sound box product has an out-of-bounds write vulnerability. Attackers can exploit this vulnerability to cause buffer overflow. AffeEPSS 0.2%CVE-2024-20743HIGHAdobe Substance 3D Paint PSD Parsing Out-Of-Bounds Write VulnerabilityEPSS 0.2%CVE-2025-4422HIGHEfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM moduleEPSS 0.2%CVE-2023-38680HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2024-20740HIGHAdobe Substance 3D Paint PSD Parsing Out-Of-Bounds Write VulnerabilityEPSS 0.2%