Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-59732HIGHHeap-buffer-overflow write in FFmpeg EXR dwa_uncompressEPSS 0.2%CVE-2025-39862HIGHwifi: mt76: mt7915: fix list corruption after hardware restartEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2023-21508MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain KeystoreEPSS 0.2%CVE-2023-21499HIGHOut-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attEPSS 0.2%CVE-2019-25569MEDIUMRealTerm Serial Terminal 2.0.0.70 SEH Overflow CrashEPSS 0.2%CVE-2023-21509MEDIUMOut-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to verEPSS 0.2%CVE-2019-25615HIGHLavavo CD Ripper 4.20 Local SEH Buffer OverflowEPSS 0.2%CVE-2026-21306HIGHSubstance3D - Sampler | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-25480HIGHVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card ReadEPSS 0.2%CVE-2023-20941MEDIUMIn acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to phyEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2026-33317HIGHOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosureEPSS 0.2%CVE-2026-40310MEDIUMImageMagick: Heap out-of-bounds write in JP2 encoderEPSS 0.2%CVE-2023-40307MEDIUMPrivileges Memory Corruption (Out-of-bound write)EPSS 0.2%CVE-2019-25584MEDIUMRarmaRadio 2.72.3 Server Field Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-32861HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass fileEPSS 0.2%CVE-2026-64204HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2019-25556MEDIUMTwistedBrush Pro Studio 24.06 Resize Image Denial of ServiceEPSS 0.2%CVE-2026-32862HIGHOut-of-Bounds Write in ResFileFactory::InitResourceMgr()EPSS 0.2%