Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-20744HIGHAdobe Substance 3D Paint PICT Parsing Access Violation Write VulnerabilityEPSS 0.2%CVE-2022-48330HIGHA Huawei sound box product has an out-of-bounds write vulnerability. Attackers can exploit this vulnerability to cause buffer overflow. AffeEPSS 0.2%CVE-2022-43397HIGHA vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35EPSS 0.2%CVE-2026-11672HIGHHeap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer pEPSS 0.2%CVE-2019-25597MEDIUMNSauditor 3.1.2.0 Denial of Service via Community FieldEPSS 0.2%CVE-2025-47724HIGHOut-of-bounds Write in CNCSoftEPSS 0.2%CVE-2019-25666MEDIUMSpotAuditor 3.6.7 Denial of Service Buffer OverflowEPSS 0.2%CVE-2026-21299HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-20402MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.2%CVE-2021-47441HIGHmlxsw: thermal: Fix out-of-bounds memory accessesEPSS 0.2%CVE-2022-3092HIGHGE CIMPLICITY Out-of-bounds WriteEPSS 0.2%CVE-2021-47535HIGHdrm/msm/a6xx: Allocate enough space for GMU registersEPSS 0.2%CVE-2026-53938HIGHOpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)EPSS 0.2%CVE-2026-5495HIGHLabcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-0183HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of serEPSS 0.2%CVE-2023-47282LOWOut-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated usEPSS 0.2%CVE-2026-5493HIGHLabcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-5494HIGHLabcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-20430HIGHIn wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalEPSS 0.2%CVE-2024-52571HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%