Falhas do tipo CWE-787

5.231 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-48239MEDIUMIn camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-48385MEDIUMIn cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2026-49918HIGHIn multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege EPSS 0.1%CVE-2022-48373MEDIUMIn tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysteEPSS 0.1%CVE-2022-48238MEDIUMIn Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystEPSS 0.1%CVE-2026-55351HIGHIn VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2026-55323HIGHIn gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%CVE-2022-48372MEDIUMIn bootcp service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2026-57014HIGHIn phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This cEPSS 0.1%CVE-2022-47486MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service witEPSS 0.1%CVE-2022-48235MEDIUMIn MP3 encoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysteEPSS 0.1%CVE-2026-45515HIGHIn a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overfEPSS 0.1%CVE-2022-47469MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with SystemEPSS 0.1%CVE-2026-28653HIGHIn multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation EPSS 0.1%CVE-2022-48240MEDIUMIn camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47485MEDIUMIn modem control device, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service wEPSS 0.1%CVE-2022-47470MEDIUMIn ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with SystemEPSS 0.1%CVE-2023-32827MEDIUMIn camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privEPSS 0.1%CVE-2023-20816MEDIUMIn wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege EPSS 0.1%CVE-2023-20720MEDIUMIn pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.1%