Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-27132LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2026-17100HIGHPower System Out-of-bounds WriteEPSS 0.2%CVE-2025-22835LOWArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2023-32472MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with higEPSS 0.2%CVE-2026-6040MEDIUMHeap use-after-free in ODF number-format blank-width parsingEPSS 0.2%CVE-2026-31797MEDIUMiccDEV has a heap out-of-bounds read in CTiffImg::ReadLine()EPSS 0.2%CVE-2021-47775HIGHYouTube Video Grabber 1.9.9.1 - Buffer Overflow (SEH)EPSS 0.2%CVE-2018-9471CRITICALIn the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local eEPSS 0.2%CVE-2026-30981MEDIUMiccDEV has a heap-buffer-overflow read in CIccXmlArrayType<>EPSS 0.2%CVE-2026-8358MEDIUMHeap buffer overflow in spreadsheet tracked-changes importEPSS 0.2%CVE-2026-63275MEDIUMStack buffer overflow in CFF font hint handlingEPSS 0.2%CVE-2024-32504HIGHAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, EEPSS 0.2%CVE-2026-63272MEDIUMHeap buffer overflow in WMF text record importEPSS 0.2%CVE-2026-28662HIGHIn p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead tEPSS 0.2%CVE-2026-6039MEDIUMHeap buffer overflow in DXF polyline importEPSS 0.2%CVE-2026-8356MEDIUMStack buffer overflow in PPT presentation importEPSS 0.2%CVE-2026-6047MEDIUMHeap buffer overflow in OOXML text box element importEPSS 0.2%CVE-2022-42503MEDIUMIn ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing EPSS 0.2%CVE-2026-16996HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-21352HIGHDNG SDK | Out-of-bounds Write (CWE-787)EPSS 0.2%