Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-44363CRITICALTenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.EPSS 0.8%CVE-2026-54626CRITICALSAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)EPSS 0.8%CVE-2024-28553CRITICALTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.EPSS 0.8%CVE-2026-42944HIGHHeap overflow with multiple NSID, COOKIE, PADDING EDNS optionsEPSS 0.8%CVE-2026-54627CRITICALSAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)EPSS 0.8%CVE-2022-47116HIGHTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.EPSS 0.8%CVE-2023-4585HIGHMemory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2EPSS 0.8%CVE-2024-41311HIGHIn Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can leaEPSS 0.8%CVE-2022-35054MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.EPSS 0.8%CVE-2022-35052MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b84b1.EPSS 0.8%CVE-2022-35045MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0d63.EPSS 0.8%CVE-2022-35056MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0478.EPSS 0.8%CVE-2022-35046MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0466.EPSS 0.8%CVE-2022-35053MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.EPSS 0.8%CVE-2022-35055MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.EPSS 0.8%CVE-2022-35047MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.EPSS 0.8%CVE-2022-35058MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05ce.EPSS 0.8%CVE-2022-35050MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.EPSS 0.8%CVE-2022-35048MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0b2c.EPSS 0.8%CVE-2026-58188HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental pluginsEPSS 0.8%