Falhas do tipo CWE-787

5.232 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2025-27054HIGHOut-of-bounds Write in DisplayEPSS 0.1%CVE-2023-32838MEDIUMIn dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-47340HIGHOut-of-bounds Write in DSP ServiceEPSS 0.1%CVE-2025-47355HIGHOut-of-bounds Write in DSP ServiceEPSS 0.1%CVE-2024-20031MEDIUMIn da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execuEPSS 0.1%CVE-2024-22009HIGHIn init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2025-20778HIGHIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%CVE-2024-20105MEDIUMIn m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicioEPSS 0.1%CVE-2022-48438HIGHIn cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2023-32873MEDIUMIn keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-32836MEDIUMIn display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with SystemEPSS 0.1%CVE-2025-20641HIGHIn DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attackEPSS 0.1%CVE-2025-36907HIGHIn draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could leEPSS 0.1%CVE-2025-20668MEDIUMIn scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicioEPSS 0.1%CVE-2025-20657MEDIUMIn vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicEPSS 0.1%CVE-2023-48342MEDIUMIn media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47337MEDIUMIn media service, there is a missing permission check. This could lead to local denial of service in media service.EPSS 0.1%CVE-2023-52348MEDIUMIn ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysteEPSS 0.1%CVE-2018-9395HIGHIn mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gEPSS 0.1%CVE-2025-36903HIGHIn lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privileEPSS 0.1%