Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-20131MEDIUMIn Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege witEPSS 0.2%CVE-2026-20745HIGHOut-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service.EPSS 0.2%CVE-2024-20132MEDIUMIn Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no addEPSS 0.2%CVE-2024-20133MEDIUMIn Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege witEPSS 0.2%CVE-2024-54091HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.2%CVE-2025-52939CRITICALPotential heap-buffer overflow vulnerability in NotepadNextEPSS 0.2%CVE-2023-20945HIGHIn phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This couEPSS 0.2%CVE-2026-16914MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2024-39816HIGHArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-59146HIGHData::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slotEPSS 0.2%CVE-2026-33144MEDIUMGPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)EPSS 0.2%CVE-2024-27365MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, ExynoEPSS 0.2%CVE-2022-42542MEDIUMIn phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead toEPSS 0.2%CVE-2026-55586MEDIUMSumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM filesEPSS 0.2%CVE-2026-19885HIGHOriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-16951MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-88390HIGHAn out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containEPSS 0.2%CVE-2026-84515HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mEPSS 0.2%CVE-2024-20079CRITICALIn gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege EPSS 0.2%CVE-2024-32056HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains an out of bounds write pastEPSS 0.2%