Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2023-5367HIGHXorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputpropertyEPSS 0.6%CVE-2024-37077HIGHArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.6%CVE-2026-2793CRITICALMemory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148EPSS 0.6%CVE-2022-25972HIGHAn out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead EPSS 0.6%CVE-2024-48856CRITICALVulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development PlatformEPSS 0.6%CVE-2026-2792CRITICALMemory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148EPSS 0.6%CVE-2022-40650HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2025-69419HIGHOut of bounds write in PKCS12_get_friendlyname() UTF-8 conversionEPSS 0.6%CVE-2023-22411HIGHJunos OS: SRX Series: The flow processing daemon (flowd) will crash when Unified Policies are used with IPv6 and certain dynamic applications are rejected by the deviceEPSS 0.6%CVE-2024-23121HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.6%CVE-2021-32419MEDIUMAn issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function EPSS 0.6%CVE-2022-3397HIGHOMRON CX-Programmer Out-of-bounds WriteEPSS 0.6%CVE-2022-3396HIGHOMRON CX-Programmer Out-of-bounds WriteEPSS 0.6%CVE-2022-3398HIGHOMRON CX-Programmer Out-of-bounds WriteEPSS 0.6%CVE-2026-40393HIGHIn Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depenEPSS 0.6%CVE-2023-6387HIGHIncorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflowEPSS 0.6%CVE-2023-30770HIGHA stack-based buffer overflow vulnerability was found in the ADMEPSS 0.6%CVE-2020-8871HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 . An attacker mEPSS 0.6%CVE-2026-26965HIGHFreeRDP has Out-of-bounds WriteEPSS 0.6%CVE-2022-32947HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app EPSS 0.6%