Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-25502HIGHiccDEV is vulnerable to stack-buffer-overflow in icFixXml()EPSS 0.2%CVE-2023-0199MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds write can EPSS 0.2%CVE-2023-5068HIGHDelta Electronics DIAScreen Out-of-bounds WriteEPSS 0.2%CVE-2025-6272MEDIUMwasm3 m3_compile.c MarkSlotAllocated out-of-bounds writeEPSS 0.2%CVE-2025-41413HIGHFuji Electric Smart Editor Out-of-bounds WriteEPSS 0.2%CVE-2023-0622HIGHCVE-2023-0622EPSS 0.2%CVE-2023-25009HIGHA malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result EPSS 0.2%CVE-2026-39853HIGHosslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature VerificationEPSS 0.2%CVE-2026-74225HIGHU-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6EPSS 0.2%CVE-2023-0623HIGHCVE-2023-0623EPSS 0.2%CVE-2026-20886MEDIUMOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service.EPSS 0.2%CVE-2026-0164HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additionalEPSS 0.2%CVE-2026-101203MEDIUMFastStone Image Viewer 1bpp RLE Decoder out-of-bounds writeEPSS 0.2%CVE-2026-0151HIGHIn IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executEPSS 0.2%CVE-2019-25644MEDIUMWinMPG Video Convert 9.3.5 Buffer Overflow Local Denial of ServiceEPSS 0.2%CVE-2026-0161HIGHIn numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escEPSS 0.2%CVE-2026-101202MEDIUMFastStone Image Viewer TGA Image out-of-bounds writeEPSS 0.2%CVE-2025-30441MEDIUMThis issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary filEPSS 0.2%CVE-2024-13044HIGHAshlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-20434HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE EPSS 0.2%