Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-47124HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2022-35219MEDIUMNHI card’s web service component - Stack-based Buffer Overflow-2EPSS 0.2%CVE-2025-47126HIGHAdobe Framemaker | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-65705HIGHFFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()EPSS 0.2%CVE-2026-92786HIGHLightGBM through 4.7.0 Out-of-Bounds Write via Crafted ModelEPSS 0.2%CVE-2025-59300MEDIUMFile Parsing Out-Of-Bounds Write Vulnerability in DIAScreenEPSS 0.2%CVE-2025-49848HIGHOut-of-bounds Write in LS Electric GMWin 4EPSS 0.2%CVE-2023-23910LOWOut-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authentiEPSS 0.2%CVE-2025-43380MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,EPSS 0.2%CVE-2026-18220HIGHBinutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processingEPSS 0.2%CVE-2025-59728HIGHHeap-buffer-overflow write in FFmpeg MDASH resolve_content_pathEPSS 0.2%CVE-2025-35971HIGHOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may alloEPSS 0.2%CVE-2019-25609HIGHJetAudio jetCast Server 2.0 Local SEH Buffer OverflowEPSS 0.2%CVE-2025-30255HIGHOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may alloEPSS 0.2%CVE-2025-59733HIGHHeap-buffer-overflow write in FFmpeg EXR dwa_uncompressEPSS 0.2%CVE-2018-25255HIGH10-Strike LANState 8.8 Local Buffer Overflow SEHEPSS 0.2%CVE-2019-25603HIGHTuneClone 2.20 Structured Exception Handler Buffer OverflowEPSS 0.2%CVE-2025-33029HIGHOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may alloEPSS 0.2%CVE-2018-25251HIGHSnes9K 0.0.9z Buffer Overflow SEH via Netplay SocketEPSS 0.2%CVE-2023-49614MEDIUMOut of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclEPSS 0.2%