Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-30371CRITICALIn Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.EPSS 0.8%CVE-2023-30368CRITICALTenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.EPSS 0.8%CVE-2023-40308HIGHMemory Corruption vulnerability in SAP CommonCryptoLibEPSS 0.8%CVE-2026-16975HIGHIBM i is Affected By A Remote Code Execution Vulnerability []EPSS 0.8%CVE-2026-17223HIGHIBM i is Affected By Multiple Vulnerabilities in Host ServersEPSS 0.8%CVE-2024-57581CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.EPSS 0.8%CVE-2023-29090MEDIUMAn issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos EPSS 0.8%CVE-2018-10878MEDIUMA flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecifiedEPSS 0.8%CVE-2024-57582CRITICALTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.EPSS 0.8%CVE-2023-29088MEDIUMAn issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos EPSS 0.8%CVE-2021-39990CRITICALThe screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experieEPSS 0.8%CVE-2026-7372CRITICALGeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerabilityEPSS 0.8%CVE-2021-40226HIGHxpdfreader 4.03 is vulnerable to Buffer Overflow.EPSS 0.8%CVE-2024-30349HIGHFoxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-2505HIGHMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2023-31567HIGHPodofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.EPSS 0.7%CVE-2022-44755CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2026-26011CRITICALCritical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance -- Potential Remote Code ExecutionEPSS 0.7%CVE-2024-20375HIGHA vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications MaEPSS 0.7%CVE-2025-62550HIGHAzure Monitor Agent Remote Code Execution VulnerabilityEPSS 0.7%