Falhas do tipo CWE-787

5.227 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-9482MEDIUMOut of Bounds write on scan of malformed Mach-O file may crash the applicationEPSS 0.1%CVE-2024-9481MEDIUMOut of Bounds write on scan of malformed eml file may crash the applicationEPSS 0.1%CVE-2026-45784MEDIUMrust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersEPSS 0.1%CVE-2026-47575HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attackerEPSS 0.1%CVE-2026-85084MEDIUMOut-of-bounds write in TizenFX MediaBufferBase indexer setter due to missing bounds checkEPSS 0.1%CVE-2026-12235MEDIUMOut-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)EPSS 0.1%CVE-2022-32632MEDIUMIn Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SyEPSS 0.1%CVE-2026-24799MEDIUMA heap-based buffer over-read or buffer overflow in davisking/dlibEPSS 0.1%CVE-2021-25408—A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2022-32631MEDIUMIn Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SyEPSS 0.1%CVE-2026-16855MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-97185HIGHGimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset fileEPSS 0.1%CVE-2024-0051HIGHIn onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatioEPSS 0.1%CVE-2022-32594MEDIUMIn widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-17195MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-13732HIGHGdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elfEPSS 0.1%CVE-2019-25463MEDIUMSpotIE Internet Explorer Password Recovery 2.9.5 Key Field DoSEPSS 0.1%CVE-2026-62363MEDIUMImageMagick: Heap Buffer Over-Write in fx operationEPSS 0.1%CVE-2019-25606MEDIUMFast AVI MPEG Joiner 1.2.0812 Buffer Overflow Denial of ServiceEPSS 0.1%CVE-2026-16783HIGHABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds MaxEPSS 0.1%