Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-13592MEDIUMliftoff-sr CIPster EtherNet IP Message append out-of-bounds writeEPSS 0.6%CVE-2026-31970HIGHHTSlib BGZF index file reader has a heap buffer overflowEPSS 0.6%CVE-2018-25220CRITICALBochs 2.6-5 Buffer Overflow Remote Code ExecutionEPSS 0.6%CVE-2022-2081HIGHA vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and coEPSS 0.6%CVE-2023-32111HIGHMemory Corruption vulnerability in SAP PowerDesigner (Proxy)EPSS 0.6%CVE-2023-43785MEDIUMLibx11: out-of-bounds memory access in _xkbreadkeysyms()EPSS 0.6%CVE-2022-41201HIGHDue to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusteEPSS 0.6%CVE-2026-2048HIGHGIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-11403MEDIUMOut of Bounds Memory Read/Write in libjxlEPSS 0.6%CVE-2022-41900HIGHFractionalMaxPool and FractionalAVGPool heap out-of-bounds acess in TensorflowEPSS 0.6%CVE-2026-90559HIGHsnappy-java through 1.1.10.8 Out-of-Bounds Write via uncompressEPSS 0.6%CVE-2025-37947HIGHksmbd: prevent out-of-bounds stream writes by validating *posEPSS 0.6%CVE-2026-53461HIGHImageMagick: Out-of-bounds write in ICON decoder due to incorrect loopEPSS 0.6%CVE-2023-22404MEDIUMJunos OS: SRX Series and MX Series with SPC3: When IPsec VPN is configured iked will core when a specifically formatted payload is receivedEPSS 0.6%CVE-2026-46520HIGHImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensionsEPSS 0.6%CVE-2026-48095HIGHGHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocationEPSS 0.6%CVE-2024-7519HIGHInsufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to peEPSS 0.6%CVE-2024-41461CRITICALTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClEPSS 0.6%CVE-2024-49195CRITICALMbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pairEPSS 0.6%CVE-2022-40961MEDIUMDuring startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>EPSS 0.6%