Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2022-43038MEDIUMBento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.EPSS 0.6%CVE-2022-33888HIGHA malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write acceEPSS 0.6%CVE-2022-39392MEDIUMWasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationEPSS 0.6%CVE-2018-16301—The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability thEPSS 0.6%CVE-2021-46764HIGHImproper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resultEPSS 0.6%CVE-2025-25742CRITICALD-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SEPSS 0.6%CVE-2022-2320—A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results frEPSS 0.6%CVE-2023-37557MEDIUMCODESYS Heap-based Buffer Overflow in multiple productsEPSS 0.6%CVE-2022-32812HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 202EPSS 0.6%CVE-2025-0236MEDIUMOut-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver EPSS 0.6%CVE-2023-49427HIGHBuffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SEPSS 0.6%CVE-2025-0234MEDIUMOut-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic EPSS 0.6%CVE-2025-0235MEDIUMOut-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 PrinEPSS 0.6%CVE-2025-30175HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < VEPSS 0.6%CVE-2025-12196HIGHWatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping CommandEPSS 0.6%CVE-2023-24122MEDIUMJensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid_5g parameter at /goform/WifiBasicEPSS 0.6%CVE-2024-27436MEDIUMALSA: usb-audio: Stop parsing channels bits when all channels are found.EPSS 0.6%CVE-2023-24123MEDIUMJensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicEPSS 0.6%CVE-2025-64657CRITICALAzure Application Gateway Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2023-5367HIGHXorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputpropertyEPSS 0.6%