Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2019-25712MEDIUMBlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration KeyEPSS 0.2%CVE-2022-29277HIGHIncorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmEPSS 0.2%CVE-2018-25268HIGHLanSpy 2.0.1.159 Local Buffer Overflow via Scan FieldEPSS 0.2%CVE-2018-9413HIGHIn handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remEPSS 0.2%CVE-2024-0429HIGHBuffer overflow vulnerability on Hex WorkshopEPSS 0.2%CVE-2021-29566LOWHeap OOB access in `Dilation2DBackpropInput`EPSS 0.2%CVE-2023-49675HIGHCODESYS: Out-of-bounds write through corrupted project filesEPSS 0.2%CVE-2023-49128HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounEPSS 0.2%CVE-2025-21650HIGHnet: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issueEPSS 0.2%CVE-2021-3721MEDIUMA denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local accEPSS 0.2%CVE-2023-39431HIGHSantesoft Sante DICOM Viewer Pro Out-of-bounds WriteEPSS 0.2%CVE-2022-29276HIGHSMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading toEPSS 0.2%CVE-2024-56740HIGHnfs/localio: must clear res.replen in nfs_local_read_doneEPSS 0.2%CVE-2022-30771HIGHInitialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm cEPSS 0.2%CVE-2022-30772HIGHManipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of EPSS 0.2%CVE-2019-25562MEDIUMjetAudio 8.1.7 Denial of Service via File Naming Buffer OverflowEPSS 0.2%CVE-2025-6633HIGHRBG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2026-47626HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write.EPSS 0.2%CVE-2026-31795HIGHiccDEV has a stack buffer overflow write in CIccXform3DLut::Apply()EPSS 0.2%CVE-2026-30987HIGHiccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()EPSS 0.2%