Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-22211MEDIUMTinyOS <= 2.1.2 Global Buffer Overflow in printfUARTEPSS 0.2%CVE-2026-77118HIGHOut-of-bounds write in GraphicsMagick PCD decoderEPSS 0.2%CVE-2024-40810MEDIUMAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cEPSS 0.2%CVE-2022-42509MEDIUMIn CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locEPSS 0.2%CVE-2022-42507MEDIUMIn ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds chEPSS 0.2%CVE-2026-88048HIGHTesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatchEPSS 0.2%CVE-2026-57260HIGHSecurity vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)EPSS 0.2%CVE-2026-86901HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciouslEPSS 0.2%CVE-2026-86313HIGHOut-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a665EPSS 0.2%CVE-2026-33850HIGHOut-of-bounds Write in WujekFoliarz DualSenseY-v2EPSS 0.2%CVE-2026-55892MEDIUMVim: Out-of-bounds Write in Spell File Prefix DumpEPSS 0.2%CVE-2025-24309LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2025-22835LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-10682MEDIUMOut-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspaceEPSS 0.2%CVE-2026-43903HIGHOpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release buildsEPSS 0.2%CVE-2026-17100HIGHPower System Out-of-bounds WriteEPSS 0.2%CVE-2025-27132LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2024-47797HIGHLiteos_a has an out-of-bounds Write vulnerabilityEPSS 0.2%CVE-2025-23240LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2024-47137HIGHLiteos_a has an out-of-bounds Write vulnerabilityEPSS 0.2%