Falhas do tipo CWE-787

5.228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-55693MEDIUMVim: Out-of-bounds Write in Spell File Word CountEPSS 0.1%CVE-2025-20656MEDIUMIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2026-33960LOWAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A mEPSS 0.1%CVE-2019-25475MEDIUMSQL Server Password Changer 1.90 Denial of Service Buffer OverflowEPSS 0.1%CVE-2025-36924HIGHIn ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This EPSS 0.1%CVE-2019-25477MEDIUMRAR Password Recovery 1.80 Denial of Service Buffer OverflowEPSS 0.1%CVE-2019-25484MEDIUMWinMPG iPod Convert 3.0 Register Field Buffer Overflow DoSEPSS 0.1%CVE-2026-46690MEDIUMunbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX raceEPSS 0.1%CVE-2019-25476MEDIUMOutlook Password Recovery 2.10 Denial of Service Buffer OverflowEPSS 0.1%CVE-2019-25469MEDIUMFolder Lock 7.7.9 Denial of Service via Serial Number FieldEPSS 0.1%CVE-2026-88839MEDIUMBusybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpointEPSS 0.1%CVE-2026-0010HIGHIn onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escEPSS 0.1%CVE-2026-19696MEDIUMOut-of-bounds Write in WiresharkEPSS 0.1%CVE-2018-25198MEDIUMeToolz 3.4.8.0 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2021-4478HIGHDräger CC-Vision Basic and CC-Vision E-Cal Out-of-Bounds Write via Malicious GDT FileEPSS 0.1%CVE-2025-14098HIGHAvira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable fileEPSS 0.1%CVE-2026-19280MEDIUMIBM i is Affected By Multiple Vulnerabilities in PASE [, ]EPSS 0.1%CVE-2025-11964LOWOOBW in utf_16le_to_utf_8_truncated() in libpcapEPSS 0.1%CVE-2025-10238HIGHDuring an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products cEPSS 0.1%CVE-2022-2984MEDIUMIn jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.EPSS 0.1%