Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-25662CRITICALTenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via theEPSS 0.4%CVE-2024-46581HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows aEPSS 0.4%CVE-2025-25678CRITICALTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.EPSS 0.4%CVE-2024-46584HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allEPSS 0.4%CVE-2024-46595HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows EPSS 0.4%CVE-2024-46588HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allowEPSS 0.4%CVE-2025-25674CRITICALTenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.EPSS 0.4%CVE-2024-53320CRITICALQualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProjEPSS 0.4%CVE-2023-4452MEDIUMWeb Server Buffer Overflow VulnerabilityEPSS 0.4%CVE-2026-7321CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC: Networking componentEPSS 0.4%CVE-2026-32741HIGHlibheif has a heap buffer overflow in decode_mask_image()EPSS 0.4%CVE-2023-39388—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause homEPSS 0.4%CVE-2023-39389—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause homEPSS 0.4%CVE-2023-39063HIGHBuffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the StepEPSS 0.4%CVE-2023-39408—DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.EPSS 0.4%CVE-2025-69720HIGHThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.EPSS 0.4%CVE-2023-39386—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newEPSS 0.4%CVE-2025-51281HIGHD-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability alEPSS 0.4%CVE-2024-40536MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the conEPSS 0.4%CVE-2024-50697HIGHIn SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not haEPSS 0.4%