Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2019-25584MEDIUMRarmaRadio 2.72.3 Server Field Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2024-7991HIGHAutodesk AutoCAD DWG Out-of-Bounds Write Code Execution VulnerabilityEPSS 0.2%CVE-2026-32862HIGHOut-of-Bounds Write in ResFileFactory::InitResourceMgr()EPSS 0.2%CVE-2026-33165MEDIUMheap out-of-bounds write in libde265 1.0.16EPSS 0.2%CVE-2026-32861HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass fileEPSS 0.2%CVE-2023-22639MEDIUMA out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6EPSS 0.2%CVE-2025-47127HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-47126HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2023-22442HIGHOut of bounds write in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of priviEPSS 0.2%CVE-2024-21972MEDIUM An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformedEPSS 0.2%CVE-2025-47132HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-65706HIGHFFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame ProcessingEPSS 0.2%CVE-2026-21342HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2025-14409HIGHSoda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-30312HIGHDimension | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-21979MEDIUM An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformedEPSS 0.2%CVE-2026-65705HIGHFFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()EPSS 0.2%CVE-2025-47124HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-35219MEDIUMNHI card’s web service component - Stack-based Buffer Overflow-2EPSS 0.2%CVE-2025-47129HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%