Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-78183CRITICALDBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_floatEPSS 0.7%CVE-2024-32608CRITICALHDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial ofEPSS 0.7%CVE-2024-20066HIGHIn modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no addiEPSS 0.7%CVE-2024-41131HIGHOut-of-bounds Write in SixLabors ImageSharpEPSS 0.7%CVE-2023-25746HIGHMemory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effEPSS 0.7%CVE-2023-0930HIGHHeap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.7%CVE-2016-20049CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer Overflow Remote Code ExecutionEPSS 0.7%CVE-2017-20227CRITICALJAD 1.5.8e-1kali1 Stack-Based Buffer OverflowEPSS 0.7%CVE-2023-25745HIGHMemory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.7%CVE-2024-35797HIGHmm: cachestat: fix two shmem bugsEPSS 0.7%CVE-2023-26551MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a clieEPSS 0.7%CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS 0.7%CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS 0.7%CVE-2025-41679MEDIUMUnauthenticated Buffer Overflow in Conftool Service Leading to Denial of ServiceEPSS 0.7%CVE-2026-23876HIGHHeap buffer overflow with attacker-controlled data in XBM parserEPSS 0.7%CVE-2024-35273HIGHA out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escEPSS 0.7%CVE-2025-49709CRITICALMemory corruption in canvas surfacesEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2022-36320CRITICALMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2022-41193—Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusEPSS 0.7%