Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-34086HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), TeamceEPSS 0.2%CVE-2024-52570HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2026-12519MEDIUMOut-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsingEPSS 0.2%CVE-2022-32961MEDIUMHiCOS’ client-side citizen digital certificate - Stack Buffer OverflowEPSS 0.2%CVE-2022-32960MEDIUMHiCOS’ client-side citizen digital certificate - Stack Buffer OverflowEPSS 0.2%CVE-2024-52565HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2022-32959MEDIUMHiCOS’ client-side citizen digital certificate - Stack Buffer OverflowEPSS 0.2%CVE-2023-3487HIGHInteger overflow in Silicon Labs Gecko Bootloader leads to unbounded memory accessEPSS 0.2%CVE-2026-87118MEDIUMBotslab G980H Dashcams Out-of-bounds WriteEPSS 0.2%CVE-2023-23579HIGHDatakit CrossCAD/WareEPSS 0.2%CVE-2024-52566HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2022-42281MEDIUMNVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bEPSS 0.2%CVE-2022-35217HIGHNHI card’s web service component - Stack-based Buffer Overflow-1EPSS 0.2%CVE-2025-47108HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-46715HIGHSandboxie Arbitrary Kernel Write in SbieDrv.sys API (API_GET_SECURE_PARAM)EPSS 0.2%CVE-2024-58069HIGHrtc: pcf85063: fix potential OOB write in PCF85063 NVMEM readEPSS 0.2%CVE-2024-0110MEDIUMNVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed EEPSS 0.2%CVE-2024-11157HIGHRockwell Automation Third Party Vulnerability in ArenaEPSS 0.2%CVE-2026-92179HIGHpdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-0199MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds write can EPSS 0.2%