Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-0957HIGHOut-Of-Bounds Write in Digilent DASYLabEPSS 0.2%CVE-2025-24442HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22327MEDIUMOut-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable inforEPSS 0.2%CVE-2025-24441HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2019-25660MEDIUMLanHelper 1.74 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2025-21919HIGHsched/fair: Fix potential memory corruption in child_cfs_rq_on_listEPSS 0.2%CVE-2025-24444HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22612HIGHAn issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler wiEPSS 0.2%CVE-2025-24445HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-47317HIGHOut-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitraEPSS 0.2%CVE-2024-53193HIGHclk: clk-loongson2: Fix memory corruption bug in struct loongson2_clk_providerEPSS 0.2%CVE-2024-22103MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%CVE-2024-54520MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura EPSS 0.2%CVE-2026-20471MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker hasEPSS 0.2%CVE-2026-14368MEDIUMOff-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parserEPSS 0.2%CVE-2017-13313HIGHIn ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due tEPSS 0.2%CVE-2021-25492HIGHLack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.EPSS 0.2%CVE-2023-32203HIGHHorner Automation Cscape Out-of-bounds WriteEPSS 0.2%CVE-2020-37140MEDIUMEverest 5.50.2100 - 'Open File' Denial of ServiceEPSS 0.2%CVE-2024-11920MEDIUMInappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memorEPSS 0.2%