Falhas do tipo CWE-787

5.145 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-35040MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b5567.EPSS 0.8%CVE-2023-20520CRITICALImproper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun EPSS 0.8%CVE-2026-70461HIGHrsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from EntryEPSS 0.8%CVE-2023-24613MEDIUMThe user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite theEPSS 0.8%CVE-2023-27805MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. This vulnerabiliEPSS 0.8%CVE-2023-27808MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. This vulneraEPSS 0.8%CVE-2023-27806MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. This vuEPSS 0.8%CVE-2023-29908MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm.EPSS 0.8%CVE-2023-29911MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.EPSS 0.8%CVE-2023-29915MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.EPSS 0.8%CVE-2023-29913MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm.EPSS 0.8%CVE-2023-29912MEDIUMH3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.EPSS 0.8%CVE-2023-29916MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.EPSS 0.8%CVE-2022-37355HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.8%CVE-2023-27802MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. This vulnerabiliEPSS 0.8%CVE-2023-27810MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. This vEPSS 0.8%CVE-2023-27801MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. This vulnerabiEPSS 0.8%CVE-2023-29917MEDIUMH3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via go parameter at /goform/aspForm.EPSS 0.8%CVE-2023-27804MEDIUMH3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. This vulnerabilitEPSS 0.8%CVE-2022-37356HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.8%