Weaknesses of type CWE-120

3,165 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-44560CRITICALowntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.EPSS 0.3%CVE-2013-1424MEDIUMBuffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.EPSS 0.3%CVE-2024-52063HIGHPotential stack buffer write overflow in Connext applications while parsing malicious XML types documentEPSS 0.3%CVE-2017-13319HIGHIn pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lEPSS 0.3%CVE-2023-52550HIGHVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.3%CVE-2023-52549HIGHVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.3%CVE-2026-71399HIGHAdobe XD | Buffer Overflow (CWE-120)EPSS 0.3%CVE-2025-3728MEDIUMSourceCodester Simple Hotel Booking System login buffer overflowEPSS 0.3%CVE-2026-31280MEDIUMAn issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of ServiceEPSS 0.3%CVE-2024-57577MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.EPSS 0.3%CVE-2024-22919HIGHswftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.EPSS 0.3%CVE-2019-25354MEDIUMiSmartViewPro 1.3.34 - Denial of ServiceEPSS 0.3%CVE-2025-7677HIGHDOS attack possibleEPSS 0.3%CVE-2024-39543HIGHJunos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crashEPSS 0.3%CVE-2024-39538HIGHJunos OS Evolved: ACX7000 Series: When multicast traffic with a specific (S,G) is received evo-pfemand crashesEPSS 0.3%CVE-2021-0115MEDIUMBuffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via lEPSS 0.3%CVE-2025-52960HIGHJunos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crashEPSS 0.3%CVE-2020-37194MEDIUMBackup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of ServiceEPSS 0.3%CVE-2020-37175MEDIUMP2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of ServiceEPSS 0.3%CVE-2023-29596HIGHBuffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a denial of service via tEPSS 0.3%