Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-68160MEDIUMHeap out-of-bounds write in BIO_f_linebuffer on short writesEPSS 0.2%CVE-2024-45185MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200,EPSS 0.2%CVE-2024-3900LOWOut-of-bounds stack array write in Xpdf 4.05 due to missing zero checkEPSS 0.2%CVE-2026-65704HIGHFFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten DecoderEPSS 0.2%CVE-2019-25550MEDIUMEncrypt PDF 2.3 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2022-33730MEDIUMHeap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical aEPSS 0.2%CVE-2022-42505MEDIUMIn ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrectEPSS 0.2%CVE-2022-42506MEDIUMIn SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local EPSS 0.2%CVE-2025-9340NONEnative encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.EPSS 0.2%CVE-2018-25266MEDIUMAngry IP Scanner 3.5.3 Denial of Service via Preferences Buffer OverflowEPSS 0.2%CVE-2026-10669HIGHXtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validationEPSS 0.2%CVE-2022-42504MEDIUMIn CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This coulEPSS 0.2%CVE-2026-71974MEDIUMU-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition ReadEPSS 0.2%CVE-2016-20038HIGHyTree 1.94-1.1 Stack-Based Buffer OverflowEPSS 0.2%CVE-2018-25215MEDIUMExcel Password Recovery Professional 8.2.0.0 Local Buffer Overflow DoSEPSS 0.2%CVE-2026-21307HIGHSubstance3D - Designer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-88053HIGHTesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddataEPSS 0.2%CVE-2024-22448MEDIUMDell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploiEPSS 0.2%CVE-2021-46779HIGHInsufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASPEPSS 0.2%CVE-2023-0186MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of EPSS 0.2%