Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-17029HIGHIBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets ExtensionEPSS 0.2%CVE-2022-42503MEDIUMIn ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing EPSS 0.2%CVE-2024-31956HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which canEPSS 0.2%CVE-2026-63275MEDIUMStack buffer overflow in CFF font hint handlingEPSS 0.2%CVE-2026-63276MEDIUMStack buffer overflow in CFF to Type 1 font conversionEPSS 0.2%CVE-2026-88051HIGHTesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fieldsEPSS 0.2%CVE-2026-21352HIGHDNG SDK | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-8358MEDIUMHeap buffer overflow in spreadsheet tracked-changes importEPSS 0.2%CVE-2021-26383HIGHInsufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a comEPSS 0.2%CVE-2026-20497MEDIUMIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.2%CVE-2026-20475MEDIUMIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2026-20477MEDIUMIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2026-20481MEDIUMIn geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.2%CVE-2026-58106LOWIncomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocationEPSS 0.2%CVE-2026-44637HIGHlibsixel: integer overflow in parserEPSS 0.2%CVE-2026-84511HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27,EPSS 0.2%CVE-2026-16936HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-20466MEDIUMIn sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, ifEPSS 0.2%CVE-2026-84611HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2024-38665MEDIUMOut-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.2%