Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2016-20043HIGHNRSS RSS Reader 0.3.9-1 Stack Buffer OverflowEPSS 0.2%CVE-2024-7671HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2024-37676HIGHAn issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.EPSS 0.2%CVE-2026-1335HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.2%CVE-2019-25670HIGHRiver Past Video Cleaner 7.6.3 Buffer Overflow via SEHEPSS 0.2%CVE-2026-47747HIGHstable-diffusion.cpp has a Heap-based Buffer OverflowEPSS 0.2%CVE-2018-25256MEDIUMIP TOOLS 2.50 Local Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2024-48241MEDIUMAn issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.EPSS 0.2%CVE-2026-46331HIGHnet/sched: fix pedit partial COW leading to page cache corruptionEPSS 0.2%CVE-2025-2632HIGHOut of Bounds Write Vulnerability in NI LabVIEW reading CPU info from cacheEPSS 0.2%CVE-2026-70632HIGHFFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI DemuxingEPSS 0.2%CVE-2024-56784HIGHdrm/amd/display: Adding array index check to prevent memory corruptionEPSS 0.2%CVE-2023-39427HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%CVE-2023-39943HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds WriteEPSS 0.2%CVE-2026-0954HIGHOut-Of-Bounds Write When Opening a Corrupt DSB File in Digilent DASYLabEPSS 0.2%CVE-2026-50264HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformatEPSS 0.2%CVE-2026-47750HIGHstable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint filesEPSS 0.2%CVE-2025-2631HIGHOut of Bounds Write Vulnerability in NI LabVIEW in InitCPUInformation()EPSS 0.2%CVE-2026-81878MEDIUMradare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parserEPSS 0.2%CVE-2023-49128HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounEPSS 0.2%