Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-64197HIGHOut Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structureEPSS 0.2%CVE-2026-64196HIGHOut Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heapEPSS 0.2%CVE-2026-84552MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2025-54275MEDIUMSubstance3D - Viewer | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-64195HIGHOut Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper validation of user-supplied dataEPSS 0.2%CVE-2026-20485MEDIUMIn HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a maliciEPSS 0.2%CVE-2024-25947MEDIUMDell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute aEPSS 0.2%CVE-2025-40762HIGHA vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002).EPSS 0.2%CVE-2026-75663HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.2%CVE-2026-72854MEDIUMmsgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized ReservationEPSS 0.2%CVE-2026-53465MEDIUMImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageEPSS 0.2%CVE-2025-33190MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit oEPSS 0.2%CVE-2025-23396HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2023-53331HIGHpstore/ram: Check start of empty przs during initEPSS 0.2%CVE-2026-41220HIGHLocal privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before buEPSS 0.2%CVE-2024-32909HIGHIn handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of priEPSS 0.2%CVE-2019-25691HIGHFaleemi Desktop Software 1.8 Local Buffer Overflow SEH DEP BypassEPSS 0.2%CVE-2026-53202HIGHaccel/ivpu: Fix signed integer truncation in IPC receiveEPSS 0.2%CVE-2022-41597LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-14297HIGHThe Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.EPSS 0.2%