Falhas do tipo CWE-787

5.228 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-54616MEDIUMOut-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2023-20632MEDIUMIn usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20740MEDIUMIn vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution pEPSS 0.1%CVE-2025-52540HIGHAn improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write OutEPSS 0.1%CVE-2023-20630MEDIUMIn usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2022-32629MEDIUMIn isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2026-21111MEDIUMOut-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.EPSS 0.1%CVE-2023-21079MEDIUMIn rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalaEPSS 0.1%CVE-2022-32628MEDIUMIn isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20966HIGHIn inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of priviEPSS 0.1%CVE-2025-48519HIGHAn improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or wEPSS 0.1%CVE-2023-20739MEDIUMIn vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution pEPSS 0.1%CVE-2026-40953MEDIUMHeap overflow in Secure Access clientsEPSS 0.1%CVE-2023-21041HIGHIn append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escaEPSS 0.1%CVE-2026-57035MEDIUMIn multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privileEPSS 0.1%CVE-2026-58773MEDIUMIn link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local esEPSS 0.1%CVE-2026-56972MEDIUMIn multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privEPSS 0.1%CVE-2026-55317MEDIUMIn printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%CVE-2026-56989MEDIUMIn multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privileEPSS 0.1%CVE-2026-55332MEDIUMIn multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%