Weaknesses of type CWE-120

3,165 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-52872LOWQTS, QuTS heroEPSS 0.4%CVE-2025-52863LOWQTS, QuTS heroEPSS 0.4%CVE-2025-40815HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.4%CVE-2025-29632MEDIUMBuffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handlEPSS 0.4%CVE-2023-26733HIGHBuffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrEPSS 0.4%CVE-2025-25474MEDIUMDCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.EPSS 0.4%CVE-2022-47657HIGHGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662EPSS 0.4%CVE-2022-47663HIGHGPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609EPSS 0.4%CVE-2024-32230HIGHFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture EPSS 0.4%CVE-2022-25687HIGHmemory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SEPSS 0.4%CVE-2026-92006HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.4%CVE-2025-5037HIGHRFA File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-44866MEDIUMA buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a DeniaEPSS 0.3%CVE-2020-37065HIGHStreamRipper32 2.6 - Buffer OverflowEPSS 0.3%CVE-2025-1372MEDIUMGNU elfutils eu-readelf readelf.c print_string_section buffer overflowEPSS 0.3%CVE-2022-40284HIGHA buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker cEPSS 0.3%CVE-2025-1587MEDIUMSourceCodester Telecom Billing Management System Add New Record main.cpp addrecords buffer overflowEPSS 0.3%CVE-2024-57184MEDIUMAn issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_EPSS 0.3%CVE-2025-53474HIGHBIG-IP iRules vulnerabilityEPSS 0.3%CVE-2025-4888MEDIUMcode-projects Pharmacy Management System Add Order Details take_order buffer overflowEPSS 0.3%