Falhas do tipo CWE-787

5.228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-24919MEDIUMOut-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-10047HIGHOut-of-bounds write in Napoca real-mode hook handler via guest-controlled SS:SP (VA-13905)EPSS 0.1%CVE-2026-24926HIGHOut-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-18413HIGHOut-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer size validationEPSS 0.1%CVE-2026-18414HIGHOut-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validationEPSS 0.1%CVE-2022-48380MEDIUMIn modem control device, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service wEPSS 0.1%CVE-2026-57455MEDIUMVim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argumentEPSS 0.1%CVE-2026-10046HIGHOut-of-bounds write in Napoca BIOS INT 0x15 E820 memory map handler (VA-13905)EPSS 0.1%CVE-2022-44431MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-102730HIGHMounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NANEPSS 0.1%CVE-2026-47496HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an outEPSS 0.1%CVE-2026-21087HIGHOut-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server priviEPSS 0.1%CVE-2026-102729MEDIUM`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with EPSS 0.1%CVE-2026-16944MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-16943HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-18842HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-91802HIGHFoxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bitmap Stride ConfusionEPSS 0.1%CVE-2026-91804HIGHFoxit PDF Editor/Reader Out-of-bounds Write Vulnerability While RenderingEPSS 0.1%CVE-2018-9338HIGHIn ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 0.1%CVE-2026-91811HIGHFoxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.1%