Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-42953HIGHOut-of-bounds write in Labcenter ProteusEPSS 0.2%CVE-2026-12927HIGHCWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a maliciousEPSS 0.2%CVE-2026-86095HIGHUnidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute NameEPSS 0.2%CVE-2026-68514MEDIUMOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep imagesEPSS 0.2%CVE-2023-49614MEDIUMOut of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclEPSS 0.2%CVE-2023-32840HIGHIn modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.2%CVE-2026-47178MEDIUMlibheif has Heap Out Of Bounds Write in unci subsystemEPSS 0.2%CVE-2025-1471HIGHEclipse OMR: Buffer overflow vulnerabilityEPSS 0.2%CVE-2018-25216MEDIUMAnyBurn 4.3 Denial of Service Local Buffer OverflowEPSS 0.2%CVE-2024-23497CRITICALOut-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow anEPSS 0.2%CVE-2025-6033HIGHMemory Corruption issue in XML_Serialize() in NI Circuit Design SuiteEPSS 0.2%CVE-2019-25567MEDIUMValentina Studio 9.0.5 Linux Buffer Overflow via Host FieldEPSS 0.2%CVE-2019-25589MEDIUMZOC Terminal 7.23.4 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2024-43096HIGHIn build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proEPSS 0.2%CVE-2018-25271MEDIUMTextpad 8.1.2 Denial of Service via Run CommandEPSS 0.2%CVE-2019-25637HIGHX-NetStat Pro 5.63 Local Buffer Overflow via EggHunterEPSS 0.2%CVE-2019-25565MEDIUMMagic Iso Maker 5.5 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2019-25566MEDIUMTransMac 12.3 Denial of Service via Volume Name FieldEPSS 0.2%CVE-2019-25650HIGHRiver Past CamDo 3.7.6 Structured Exception Handler Buffer OverflowEPSS 0.2%CVE-2026-20407CRITICALIn wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilEPSS 0.2%