Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2018-25262MEDIUMAngry IP Scanner for Linux 3.5.3 Denial of ServiceEPSS 0.2%CVE-2022-20580MEDIUMIn ufdt_do_one_fixup of ufdt_overlay.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local eEPSS 0.2%CVE-2022-20576MEDIUMIn externalOnRequest of rilapplication.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local EPSS 0.2%CVE-2022-20579MEDIUMIn RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could leaEPSS 0.2%CVE-2022-20577MEDIUMIn OemSimAuthRequest::encode of wlandata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 0.2%CVE-2022-20594MEDIUMIn updateStart of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalEPSS 0.2%CVE-2025-61859HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafteEPSS 0.2%CVE-2021-26402HIGHInsufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write parEPSS 0.2%CVE-2025-61857HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening speciallyEPSS 0.2%CVE-2024-4141LOWOut-of-bounds array write in Xpdf 4.05 due to incorrect bounds checkEPSS 0.2%CVE-2019-25648MEDIUMMyVideoConverter Pro 3.14 Denial of Service Buffer OverflowEPSS 0.2%CVE-2026-41990MEDIUMLibgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.EPSS 0.2%CVE-2023-25537MEDIUM Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vuEPSS 0.2%CVE-2025-2480HIGHSantesoft Sante DICOM Viewer Pro Out-of-bounds WriteEPSS 0.2%CVE-2025-61858HIGHAn out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT fEPSS 0.2%CVE-2018-25253MEDIUMTermite 3.4 Denial of Service via Settings Buffer OverflowEPSS 0.2%CVE-2026-43666MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and EPSS 0.2%CVE-2026-45684MEDIUMOpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffersEPSS 0.2%CVE-2026-6676HIGHAvira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archiveEPSS 0.2%CVE-2022-42519MEDIUMIn CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lEPSS 0.2%