Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-54789HIGHmod_auth_openidc has out-of-bounds read and write in state cookie parsingEPSS 0.7%CVE-2023-45985HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the functioEPSS 0.7%CVE-2026-44421HIGHFreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypassEPSS 0.7%CVE-2026-43790CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A EPSS 0.7%CVE-2024-7535HIGHInappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption EPSS 0.7%CVE-2024-25448HIGHAn issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafteEPSS 0.7%CVE-2026-37457HIGHAn off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stablEPSS 0.7%CVE-2025-0690MEDIUMGrub2: read: integer overflow may lead to out-of-bounds writeEPSS 0.7%CVE-2023-6931HIGHOut-of-bounds write in Linux kernel's Performance Events system componentEPSS 0.7%CVE-2021-47772HIGH10-Strike Network Inventory Explorer Pro 9.31 - Buffer Overflow (SEH)EPSS 0.7%CVE-2023-31488CRITICALHyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, CiscoEPSS 0.7%CVE-2023-33552HIGHHeap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code viaEPSS 0.7%CVE-2022-37937CRITICALPre-auth memory corruption in HPE ServiceguardEPSS 0.7%CVE-2022-34485CRITICALMozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of thesEPSS 0.7%CVE-2022-42932HIGHMozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some oEPSS 0.7%CVE-2022-4608HIGHA vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can onlyEPSS 0.7%CVE-2026-56786CRITICALRTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 MessageEPSS 0.7%CVE-2024-25200HIGHEspruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.EPSS 0.7%CVE-2023-26064CRITICALCertain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.EPSS 0.7%CVE-2020-27005—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%