Falhas do tipo CWE-787

5.232 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2017-13323HIGHIn String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privEPSS 0.1%CVE-2022-47369MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-32879MEDIUMIn battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2026-23791MEDIUMAn issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-boundsEPSS 0.1%CVE-2024-20053HIGHIn flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2023-20809MEDIUMIn vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystemEPSS 0.1%CVE-2018-9367HIGHIn FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. TEPSS 0.1%CVE-2025-20698MEDIUMIn Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2018-9372HIGHIn cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a loEPSS 0.1%CVE-2023-20699MEDIUMIn adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with SystemEPSS 0.1%CVE-2024-20029HIGHIn wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilegeEPSS 0.1%CVE-2018-9366HIGHIn IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer oveEPSS 0.1%CVE-2024-27226HIGHIn tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of EPSS 0.1%CVE-2023-20721HIGHIn isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2025-20697MEDIUMIn Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2018-9409HIGHIn HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead tEPSS 0.1%CVE-2022-47340MEDIUMIn h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service wiEPSS 0.1%CVE-2024-20104HIGHIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2018-9368MEDIUMIn mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This couEPSS 0.1%CVE-2025-20798HIGHIn battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%