Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-2569HIGH A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kerneEPSS 0.2%CVE-2026-20416HIGHIn pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a maliciEPSS 0.2%CVE-2026-68515HIGHOpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel unionEPSS 0.2%CVE-2019-25665MEDIUMRiver Past Ringtone Converter 2.7.6.1601 Buffer Overflow DoSEPSS 0.2%CVE-2026-20446MEDIUMIn sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker EPSS 0.2%CVE-2019-25546MEDIUMNetAware 1.20 Share Name Denial of ServiceEPSS 0.2%CVE-2025-1292MEDIUMTPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOSEPSS 0.2%CVE-2019-25667MEDIUMTaskInfo 8.2.0.280 Denial of Service Buffer OverflowEPSS 0.2%CVE-2019-25545MEDIUMTerminal Services Manager 3.2.1 Local Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2022-21804HIGHOut-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentiallEPSS 0.2%CVE-2019-25695HIGHR 3.4.4 Local Buffer Overflow Windows XP SP3EPSS 0.2%CVE-2025-24185MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, mEPSS 0.2%CVE-2023-21509MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to verEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2025-1924MEDIUMA vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciousEPSS 0.2%CVE-2026-84546HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2019-25547MEDIUMNetAware 1.20 Denial of Service via Add Block Buffer OverflowEPSS 0.2%CVE-2019-25569MEDIUMRealTerm Serial Terminal 2.0.0.70 SEH Overflow CrashEPSS 0.2%CVE-2023-21499HIGHOut-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attEPSS 0.2%CVE-2023-21508MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain KeystoreEPSS 0.2%