Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2026-34124HIGHDenial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WSEPSS 0.4%CVE-2025-50401CRITICALMercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.EPSS 0.4%CVE-2026-9625HIGHRSLinx Classic® - Multiple VulnerabilitiesEPSS 0.4%CVE-2025-12011CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%CVE-2024-51409MEDIUMBuffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed foEPSS 0.4%CVE-2025-12012CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%CVE-2026-54257CRITICALElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowEPSS 0.4%CVE-2023-28562CRITICALBuffer Copy Without Checking Size of Input in QESLEPSS 0.4%CVE-2025-50258HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.EPSS 0.4%CVE-2025-50263HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.EPSS 0.4%CVE-2023-2597HIGHIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size oEPSS 0.4%CVE-2026-39869MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.4%CVE-2024-33809MEDIUMPingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service atEPSS 0.4%CVE-2019-10882MEDIUMNetskope client buffer overflow vulnerabilityEPSS 0.4%CVE-2024-57544MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stackEPSS 0.4%CVE-2026-24110CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addEPSS 0.4%CVE-2025-43520MEDIUMA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPaEPSS 0.4%KEVCVE-2024-57545MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the EPSS 0.4%CVE-2026-24103CRITICALA buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.EPSS 0.4%CVE-2023-5139MEDIUMPotential buffer overflow vulnerability in the Zephyr STM32 Crypto driverEPSS 0.4%