Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-43774MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2023-32466MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with higEPSS 0.2%CVE-2023-21085HIGHIn nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remoteEPSS 0.2%CVE-2026-49839HIGHjq --rawfile invalid-state reuse after String too long causes heap-buffer-overflowEPSS 0.2%CVE-2026-58087HIGHHeap out-of-bounds access in semctl(2)EPSS 0.2%CVE-2024-22273HIGHThe storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access tEPSS 0.2%CVE-2025-11795HIGHJPG File Parsing Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2025-65086HIGHOut-of-bounds write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2026-21305HIGHSubstance3D - Painter | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2024-38665MEDIUMOut-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.2%CVE-2024-4976LOWOut-of-bounds array write in Xpdf 4.05 due to missing object type checkEPSS 0.2%CVE-2024-27370MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-59948HIGHComposer: Arbitrary file write outside vendor via malicious transitive package nameEPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2024-27383MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-64725HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.2%CVE-2026-8718HIGHOut-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLSEPSS 0.2%CVE-2026-62291MEDIUMlibheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensionsEPSS 0.2%CVE-2024-27373MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-53705HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Out-of-bounds WriteEPSS 0.2%