Falhas do tipo CWE-787

5.238 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-24073HIGHOut-of-bounds Write in VideoEPSS 0.1%CVE-2026-58734HIGHIn google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalEPSS 0.1%CVE-2026-0153HIGHIn Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalaEPSS 0.1%CVE-2026-58701HIGHIn trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalatEPSS 0.1%CVE-2026-0150HIGHIn ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to EPSS 0.1%CVE-2023-20736MEDIUMIn vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System executEPSS 0.1%CVE-2025-27070HIGHOut-of-bounds Write in Windows ComputeEPSS 0.1%CVE-2026-104036MEDIUMSssd: sssd: denial of service via out-of-bounds write in nfs idmap pluginEPSS —CVE-2026-25269MEDIUMOut-of-bounds Write in Camera DriverEPSS —CVE-2026-49878HIGHIn wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This coulEPSS —CVE-2026-84854HIGHOut of Bound Write on WibuKey for WindowsEPSS —CVE-2026-25263MEDIUMOut of Bounds write in Linux CameraEPSS —CVE-2026-0482MEDIUMIn AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafEPSS —CVE-2026-25273MEDIUMOut-of-bounds Write in Camera DriverEPSS —CVE-2026-25270MEDIUMOut-of-bounds Write in Camera DriverEPSS —CVE-2026-0461HIGHInsufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded EPSS —CVE-2026-25272MEDIUMOut-of-bounds Write in Camera DriverEPSS —CVE-2026-59783LOWServer DoS via binary itemsEPSS —