Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-19773CRITICALlibwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-53266HIGHnetfilter: bridge: make ebt_snat ARP rewrite writableEPSS 0.6%KEVCVE-2023-48194MEDIUMVulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qosEPSS 0.6%CVE-2023-1945MEDIUMUnexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerabilEPSS 0.6%CVE-2024-39840HIGHFactorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain EPSS 0.6%CVE-2026-56340HIGHvLLM - Denial of Service via Unvalidated Multimodal EmbeddingsEPSS 0.6%CVE-2026-56209HIGHLibaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijackEPSS 0.6%CVE-2026-13053HIGHWatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command HandlerEPSS 0.6%CVE-2026-13050HIGHWatchGuard Firebox networkd Out of Bounds Write VulnerabilityEPSS 0.6%CVE-2024-29176HIGHDell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacEPSS 0.6%CVE-2026-34265CRITICALMemory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP PlatformEPSS 0.6%CVE-2026-24253HIGHNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerabEPSS 0.6%CVE-2024-0142MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted EPSS 0.6%CVE-2026-89266HIGHstb_vorbis through 1.22 heap buffer overflow via codebook multiplicandsEPSS 0.6%CVE-2026-60094MEDIUMVinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_serverEPSS 0.6%CVE-2023-26552MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a cliEPSS 0.6%CVE-2023-26554MEDIUMmstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a clEPSS 0.6%CVE-2026-54211CRITICALTeamDavid: Buffer Overflow in multiple form data parametersEPSS 0.6%CVE-2024-23123HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.6%CVE-2022-46879HIGHMozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safetyEPSS 0.6%