Weaknesses of type CWE-120

3,165 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2024-25580MEDIUMAn issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x befEPSS 0.3%CVE-2023-51793HIGHBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.cEPSS 0.3%CVE-2022-29974MEDIUMAMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used EPSS 0.3%CVE-2023-3164MEDIUMHeap-buffer-overflow in extractimagesection()EPSS 0.3%CVE-2024-45620LOWLibopensc: incorrect handling of the length of buffers or files in pkcs15initEPSS 0.3%CVE-2024-46952HIGHAn issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stEPSS 0.3%CVE-2020-37179MEDIUMAPKF Product Key Finder 2.5.8.0 - 'Name' Denial of ServiceEPSS 0.3%CVE-2023-51798HIGHBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exceptiEPSS 0.3%CVE-2022-47656HIGHGPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:EPSS 0.3%CVE-2020-37195MEDIUMBlueAuditor 1.7.2.0 - 'Name' Denial of ServiceEPSS 0.3%CVE-2020-37185MEDIUMBackup Key Recovery 2.2.5 - 'Name' Denial of ServiceEPSS 0.3%CVE-2026-12192HIGHGALAYOU Y4 Web Server buffer overflowEPSS 0.3%CVE-2022-47658HIGHGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:EPSS 0.3%CVE-2022-47654HIGHGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:EPSS 0.3%CVE-2025-65102HIGHPJSIP is vulnerable to buffer overflow in Opus PLCEPSS 0.3%CVE-2023-27590HIGHRizin has stack-based buffer overflow when parsing GDB registers profile filesEPSS 0.3%CVE-2026-24810CRITICALA buffer overflow in rethinkdb/rethinkdbEPSS 0.3%CVE-2022-47087HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.cEPSS 0.3%CVE-2022-47089HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.cEPSS 0.3%CVE-2022-47088HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.EPSS 0.3%