Falhas do tipo CWE-787

5.229 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-55332MEDIUMIn multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privEPSS 0.1%CVE-2023-20604MEDIUMIn ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2022-32634MEDIUMIn ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2023-20701MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-32806MEDIUMIn wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege wEPSS 0.1%CVE-2024-22005HIGHthere is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additionalEPSS 0.1%CVE-2025-48540HIGHIn processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead EPSS 0.1%CVE-2022-32625MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-20700MEDIUMIn widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2023-20837MEDIUMIn seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2023-32811MEDIUMIn connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalationEPSS 0.1%CVE-2023-20931HIGHIn avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to locaEPSS 0.1%CVE-2025-48624HIGHIn multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local eEPSS 0.1%CVE-2023-21046MEDIUMIn ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2022-32626MEDIUMIn display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2026-0119MEDIUMIn usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physicEPSS 0.1%CVE-2022-47470MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with SystemEPSS 0.1%CVE-2026-55351HIGHIn VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-21051MEDIUMIn dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2026-55323HIGHIn gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%