Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-29035HIGHCivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate DecompressionEPSS 0.6%CVE-2021-33656—When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.EPSS 0.6%CVE-2022-41187—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.6%CVE-2022-41190—Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrustedEPSS 0.6%CVE-2026-5731CRITICALMemory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.6%CVE-2023-32154HIGHMikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-20819MEDIUMIn CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privileEPSS 0.6%CVE-2026-32636MEDIUMImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crashEPSS 0.6%CVE-2022-41191HIGHDue to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusEPSS 0.6%CVE-2022-41199HIGHDue to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sEPSS 0.6%CVE-2026-84383CRITICALlibheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` itemsEPSS 0.6%CVE-2022-41195—Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received fromEPSS 0.6%CVE-2024-6259HIGHBT: HCI: adv_ext_report Improper discarding in adv_ext_reportEPSS 0.6%CVE-2021-3330HIGHRCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in ZephyrEPSS 0.6%CVE-2024-6443MEDIUMzephyr: out-of-bound read in utf8_truncEPSS 0.6%CVE-2026-78008HIGHFireware OS Authenticated Buffer Overflow in wgagentEPSS 0.6%CVE-2024-30373HIGHKofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-50538HIGHlibvncclient Tight decoder has an attacker-controlled heap out-of-bounds writeEPSS 0.6%CVE-2026-3548HIGHBuffer overflow in CRL number parsing in wolfSSLEPSS 0.6%CVE-2021-20233—A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumEPSS 0.6%