Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-58188HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental pluginsEPSS 0.8%CVE-2024-7973HIGHHeap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read viaEPSS 0.8%CVE-2023-35110HIGHAn issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that EPSS 0.8%CVE-2023-34612HIGHAn issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object thaEPSS 0.8%CVE-2026-32875HIGHUltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loopEPSS 0.8%CVE-2025-20634HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has conneEPSS 0.8%CVE-2023-48111HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulneraEPSS 0.8%CVE-2022-45689HIGHhutool-json v5.8.10 was discovered to contain an out of memory error.EPSS 0.8%CVE-2023-48110HIGHTenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerabEPSS 0.8%CVE-2022-41989CRITICALCVE-2022-41989EPSS 0.8%CVE-2024-57580CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.EPSS 0.8%CVE-2023-50986HIGHTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.EPSS 0.8%CVE-2022-37453HIGHAn issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and EPSS 0.8%CVE-2022-35049MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.EPSS 0.8%CVE-2022-35059MEDIUMOTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0414.EPSS 0.8%CVE-2018-10881MEDIUMA flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denEPSS 0.8%CVE-2026-3849MEDIUMBuffer Overflow in HPKE via Oversized ECH ConfigEPSS 0.8%CVE-2024-52963LOWA out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4EPSS 0.8%CVE-2024-30348HIGHFoxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-30355HIGHFoxit PDF Reader AcroForm Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.8%