Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2024-5267HIGHSonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-47868CRITICALApache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition.EPSS 0.7%CVE-2023-43862HIGHD-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.EPSS 0.7%CVE-2022-30904HIGHIn Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no cEPSS 0.7%CVE-2026-33901HIGHImageMagick has a Heap Buffer Overflow via MVG decoderEPSS 0.7%CVE-2022-45781HIGHBuffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.EPSS 0.7%CVE-2026-7831HIGHUltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsingEPSS 0.7%CVE-2023-34611HIGHAn issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that EPSS 0.7%CVE-2020-15212HIGHOut of bounds access in tensorflow-liteEPSS 0.7%CVE-2023-25732HIGHWhen encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated pEPSS 0.7%CVE-2021-47354HIGHdrm/sched: Avoid data corruptionsEPSS 0.7%CVE-2026-16095HIGHShibby Tomato rc setup_conntrack out-of-bounds writeEPSS 0.7%CVE-2023-31922HIGHQuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.EPSS 0.7%CVE-2023-29994HIGHIn NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.EPSS 0.7%CVE-2023-34615HIGHAn issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object thatEPSS 0.7%CVE-2023-29995HIGHIn NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.cEPSS 0.7%CVE-2026-15545HIGHShibby Tomato apcupsd tomatodata.cgi main out-of-bounds writeEPSS 0.7%CVE-2023-34617HIGHAn issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uEPSS 0.7%CVE-2023-34616HIGHAn issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object thatEPSS 0.7%CVE-2023-45678MEDIUMOff-by-one heap buffer write in start_decoder in stb_vorbisEPSS 0.7%