Falhas do tipo CWE-787

5.228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-47541HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds wEPSS 0.1%CVE-2026-47498HIGHNVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds writeEPSS 0.1%CVE-2026-88832HIGHBusybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflowEPSS 0.1%CVE-2026-47503HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an ouEPSS 0.1%CVE-2026-73066MEDIUMTesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddataEPSS 0.1%CVE-2026-91815HIGHFoxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.1%CVE-2025-0034MEDIUMInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_SPATIAL_PART and cauEPSS 0.1%CVE-2024-0050HIGHIn getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could leadEPSS 0.1%CVE-2022-25697HIGHMemory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon Mobile, SnEPSS 0.1%CVE-2022-20546MEDIUMIn getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2026-73072HIGHVim: Heap Buffer Overflow when Loading a Spell FileEPSS 0.1%CVE-2024-32855LOWDell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker witEPSS 0.1%CVE-2024-25993HIGHIn tmu_reset_tmu_trip_counter of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2025-62862MEDIUMAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorreEPSS 0.1%CVE-2026-91142LOWCockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 buildsEPSS 0.1%CVE-2026-33960LOWAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A mEPSS 0.1%CVE-2025-20656MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2025-0010MEDIUMAn out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting in loss of confidenEPSS 0.1%CVE-2023-32837HIGHIn video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2026-55693MEDIUMVim: Out-of-bounds Write in Spell File Word CountEPSS 0.1%