Falhas do tipo CWE-787

5.227 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-9805LOWFMTSWriteUseIntelLib: FMTS SMM IHISI Buffer OverflowEPSS 0.1%CVE-2026-90947HIGHGimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset fileEPSS 0.1%CVE-2022-20526LOWIn CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to localEPSS 0.1%CVE-2022-33218HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2022-32637MEDIUMIn hevc decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege witEPSS 0.1%CVE-2022-20548HIGHIn setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local eEPSS 0.1%CVE-2022-20549MEDIUMIn authToken2AidlVec of KeyMintUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to localEPSS 0.1%CVE-2026-102514HIGHOut-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archiveEPSS 0.1%CVE-2022-20539MEDIUMIn parameterToHal of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation EPSS 0.1%CVE-2022-20583MEDIUMIn ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local EPSS 0.1%CVE-2024-51510HIGHOut-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.1%CVE-2026-76920MEDIUMOut-of-bounds Write in WiresharkEPSS 0.1%CVE-2021-25396MEDIUMAn improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2026-17422CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-33536MEDIUMImageMagick has an Out-of-bounds Write via InterpretImageFilenameEPSS 0.1%CVE-2026-16233HIGHOut-of-Bounds Write Vulnerability in NI LabVIEW when loading VIEPSS 0.1%CVE-2026-47503HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an ouEPSS 0.1%CVE-2026-47541HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds wEPSS 0.1%CVE-2026-47498HIGHNVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds writeEPSS 0.1%CVE-2022-25698HIGHMemory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, SnaEPSS 0.1%