Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-55611CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.EPSS 0.4%CVE-2021-46882HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-34055HIGHjhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.EPSS 0.4%CVE-2021-46884HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2024-28565MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the pEPSS 0.4%CVE-2021-46883HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2022-48497—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46885HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-46881HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2025-48721LOWQTS, QuTS heroEPSS 0.4%CVE-2021-46886HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2022-48501HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-48490—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2025-1368MEDIUMMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflowEPSS 0.4%CVE-2021-47798MEDIUMNoteBurner 2.35 - Denial Of Service (DoS) (PoC)EPSS 0.4%CVE-2024-57537MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack withoEPSS 0.4%CVE-2020-14374—A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffeEPSS 0.4%CVE-2024-25373MEDIUMTenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.EPSS 0.4%CVE-2024-22905HIGHBuffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSeEPSS 0.4%CVE-2025-12011CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%