Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2024-48986HIGHAn issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byEPSS 0.5%CVE-2026-45811HIGHApache NimBLE: Buffer overflow in socket HCI transportEPSS 0.5%CVE-2024-29244MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /applEPSS 0.5%CVE-2024-48982HIGHAn issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byEPSS 0.5%CVE-2021-23159—A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability isEPSS 0.5%CVE-2025-46789MEDIUMZoom Clients for Windows - Classic Buffer OverflowEPSS 0.5%CVE-2020-37075HIGHLanSend 3.2 - Buffer Overflow (SEH)EPSS 0.5%CVE-2020-37070HIGHCloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)EPSS 0.5%CVE-2025-0689HIGHGrub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code executionEPSS 0.5%CVE-2023-50010HIGHFFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id fEPSS 0.5%CVE-2026-28925HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoeEPSS 0.5%CVE-2026-84512HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2026-36228HIGHBuffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code viEPSS 0.5%CVE-2021-42757MEDIUMA buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated lEPSS 0.5%CVE-2026-76695MEDIUMUnauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2023-24548MEDIUMOn affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packetsEPSS 0.5%CVE-2026-88409HIGHFalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matriEPSS 0.5%CVE-2026-12328HIGHMemory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152EPSS 0.5%CVE-2024-50838MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. EPSS 0.5%CVE-2023-52729HIGHTCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of lEPSS 0.5%