Falhas do tipo CWE-787

5.210 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-39181HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected application contains an out of boundEPSS 0.2%CVE-2023-27399HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-42873HIGHThe issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 EPSS 0.2%CVE-2026-10664MEDIUMOut-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)EPSS 0.2%CVE-2026-40916MEDIUMGimp: gimp: denial of service due to stack buffer overflow in tim image loaderEPSS 0.2%CVE-2026-25583HIGHiccDEV vulnerable to Heap Buffer Overflow in CIccFileIO::Read8()EPSS 0.2%CVE-2023-27398HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of EPSS 0.2%CVE-2023-34402HIGHMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, whicEPSS 0.2%CVE-2026-25582HIGHiccDEV vulnerable to Heap Buffer Overflow in CIccIO::WriteUInt16Float()EPSS 0.2%CVE-2025-47750HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6MemInIF!set_temp_type_default function. Opening specially crafteEPSS 0.2%CVE-2022-41743HIGHNGINX ngx_http_hls_module vulnerability CVE-2022-41743EPSS 0.2%CVE-2023-52512MEDIUMpinctrl: nuvoton: wpcm450: fix out of bounds writeEPSS 0.2%CVE-2026-10644MEDIUMOut-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte bufferEPSS 0.2%CVE-2025-47752HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6ComFile!MakeItemGlidZahyou function. Opening specially crafted VEPSS 0.2%CVE-2023-42871HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to eEPSS 0.2%CVE-2025-47751HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. OpeningEPSS 0.2%CVE-2026-21298HIGHSubstance3D - Modeler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2018-25226MEDIUMFTPShell Server 6.83 Denial of Service via Account NameEPSS 0.2%CVE-2026-27622HIGHOpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB writeEPSS 0.2%CVE-2018-25228MEDIUMNetSetMan 4.7.1 Workgroup Buffer Overflow Denial of ServiceEPSS 0.2%