Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-22831MEDIUMBuffer Overflow in NTFS when parsing the VOLUME_NAMEEPSS 0.1%CVE-2026-65609LOWOut-of-bounds write in nnnEPSS 0.1%CVE-2026-88049HIGHTesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatchEPSS 0.1%CVE-2025-22832MEDIUMBuffer Overflow in NTFS when parsing the ATTRIBUTE_LISTEPSS 0.1%CVE-2026-88050MEDIUMTesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code valuesEPSS 0.1%CVE-2026-84531MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27.EPSS 0.1%CVE-2025-42971MEDIUMMemory Corruption vulnerability in SAPCAREPSS 0.1%CVE-2026-25569HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SEPSS 0.1%CVE-2026-48724MEDIUMImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth ditheringEPSS 0.1%CVE-2026-24809MEDIUMSave stack space while handling errors in praydog/REFrameworkEPSS 0.1%CVE-2024-5679HIGHCWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor witEPSS 0.1%CVE-2026-53194HIGHUSB: serial: kl5kusb105: fix bulk-out buffer overflowEPSS 0.1%CVE-2026-55059MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerabilityEPSS 0.1%CVE-2026-75658HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2026-34238MEDIUMImageMagick: Integer overflow in despeckle operation causes heap buffer overflow on 32-bit buildsEPSS 0.1%CVE-2026-102566HIGHCTranslate2 before 4.8.1 Heap Buffer Overflow via model.binEPSS 0.1%CVE-2025-10451HIGHH19Int15CallbackSmm: SMM memory corruption vulnerability in combined DXE/SMM (SMRAM write)EPSS 0.1%CVE-2016-20037HIGHxwpe 1.5.30a-2.1 Stack-based Buffer OverflowEPSS 0.1%CVE-2026-46521MEDIUMImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compressionEPSS 0.1%CVE-2026-8916MEDIUMOut-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b04EPSS 0.1%