Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-43744MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 anEPSS 0.2%CVE-2025-59729MEDIUMHeap-buffer-overflow read in FFmpeg DHAV get_durationEPSS 0.2%CVE-2026-43816MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6,EPSS 0.2%CVE-2023-21476HIGHOut-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrarEPSS 0.2%CVE-2025-59730MEDIUMHeap-buffer-overflow write in FFmpeg SANM decoding due to lack of bounds-checking in old_codec48EPSS 0.2%CVE-2026-25194LOWOut-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileEPSS 0.2%CVE-2018-9388HIGHIn store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or inEPSS 0.2%CVE-2026-50144HIGHncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter idEPSS 0.2%CVE-2026-20023MEDIUMA vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat DeEPSS 0.2%CVE-2026-4016MEDIUMGPAC SVG Parser load_svg.c svgin_process out-of-bounds writeEPSS 0.2%CVE-2026-84619MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mEPSS 0.2%CVE-2025-39821HIGHperf: Avoid undefined behavior from stopping/starting inactive eventsEPSS 0.2%CVE-2019-25656HIGHR i386 3.5.0 Local Buffer Overflow SEHEPSS 0.2%CVE-2026-7582MEDIUMAcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds writeEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2024-29222MEDIUMOut-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via lEPSS 0.2%CVE-2026-84567MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2026-20468MEDIUMIn apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicEPSS 0.2%CVE-2026-20485MEDIUMIn HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a maliciEPSS 0.2%CVE-2025-40762HIGHA vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002).EPSS 0.2%