Falhas do tipo CWE-787

5.146 resultados

Escrita fora dos limites de memória

Ocorre quando um programa escreve dados em um endereço de memória fora da área alocada para um buffer ou variável. O código não valida o tamanho ou índice antes de gravar, permitindo sobrescrita de dados adjacentes, corrupção de estruturas críticas ou execução de código arbitrário.

Exemplo

Um formulário web que copia dados do usuário para um buffer de 256 bytes sem validar o tamanho da entrada. Se o atacante envia 500 bytes, a escrita transborda e sobrescreve a pilha, podendo hijackear o endereço de retorno da função.

Como mitigar

Use funções seguras de cópia (strncpy, strlcpy ao invés de strcpy; memcpy com tamanho máximo explícito) e sempre valide comprimento e índices antes de escrever. Em linguagens modernas, prefira estruturas com bounds-checking automático (arrays em Java, Rust, etc).

CVE-2026-3548HIGHBuffer overflow in CRL number parsing in wolfSSLEPSS 0.6%CVE-2024-23611HIGHOut of Bounds Write Due to Missing Bounds Check in LabVIEWEPSS 0.6%CVE-2026-3298HIGHOut-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytesEPSS 0.6%CVE-2026-58096HIGHppp(8): missing length validation in LcpDecodeConfig()EPSS 0.6%CVE-2026-8946HIGHIncorrect boundary conditions in the Audio/Video: Web Codecs componentEPSS 0.6%CVE-2025-43421MEDIUMMultiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS TaEPSS 0.6%CVE-2023-35871HIGHMemory Corruption vulnerability in SAP Web DispatcherEPSS 0.6%CVE-2017-20229CRITICALMAWK 1.3.3-17 Stack-Based Buffer OverflowEPSS 0.6%CVE-2026-10665HIGHHeap buffer overflow on WireGuard receive path via unbounded incoming packet lengthEPSS 0.6%CVE-2023-4735MEDIUMOut-of-bounds Write in vim/vimEPSS 0.6%CVE-2026-18022HIGHpgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systemsEPSS 0.6%CVE-2024-47897HIGHGPU DDK - PVRSRVRGXGetEnabledHWPerfBlocksKM off-by-one OOB writeEPSS 0.6%CVE-2026-59691HIGHGstreamer1-plugins-bad-free: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebufferEPSS 0.6%CVE-2026-40493CRITICALSAIL has heap buffer overflow in PSD decoder — bpp mismatch in LAB 16-bit modeEPSS 0.6%CVE-2026-27703HIGHRIOT has an Out-of-Bounds Write in nanoCoAP HandlerEPSS 0.6%CVE-2024-24423HIGHThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overfEPSS 0.6%CVE-2024-24422HIGHThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflEPSS 0.6%CVE-2026-57159HIGHPJSIP: SDP parser out-of-bounds write in remote payload-type map maintenanceEPSS 0.6%CVE-2024-2615CRITICALMemory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2022-41202HIGHDue to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrustedEPSS 0.6%