Falhas do tipo CWE-787

5.212 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-21349HIGHLightroom Desktop | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2026-10587MEDIUMA potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System ManagemeEPSS 0.1%CVE-2023-20513LOWAn insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) tEPSS 0.1%CVE-2026-46145HIGHRDMA/mana: Validate rx_hash_key_lenEPSS 0.1%CVE-2025-24304LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.1%CVE-2026-78547MEDIUMOut-of-Bounds WriteEPSS 0.1%CVE-2026-21341HIGHSubstance3D - Stager | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2019-25604HIGHDVDXPlayer Pro 5.5 Local Buffer Overflow with SEHEPSS 0.1%CVE-2023-47252MEDIUMAn issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM commuEPSS 0.1%CVE-2016-20039HIGHMulti Emulator Super System 0.154-3.1 Buffer OverflowEPSS 0.1%CVE-2026-21346HIGHBridge | Out-of-bounds Write (CWE-787)EPSS 0.1%CVE-2024-34776LOWOut-of-bounds write in some Intel(R) SGX SDK software may allow an authenticated user to potentially enable escalation of privilege via locaEPSS 0.1%CVE-2025-65001HIGHFujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.EPSS 0.1%CVE-2025-11266MEDIUMGrassroots DICOM (GDCM) Out-of-bounds WriteEPSS 0.1%CVE-2019-25659MEDIUMASPRunner Professional 6.0.766 Local Buffer Overflow DoSEPSS 0.1%CVE-2026-61389HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2026-24795MEDIUMAn Out-of-bounds Write in CloverHackyColor/CloverBootloaderEPSS 0.1%CVE-2026-60063HIGHAutomationDirect Productivity Suite Out-of-bounds WriteEPSS 0.1%CVE-2025-32022MEDIUMFinit has heap based buffer overwrite in urandom.so pluginEPSS 0.1%CVE-2026-20476MEDIUMIn ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User executioEPSS 0.1%