Weaknesses of type CWE-120

3,165 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2022-47089HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.cEPSS 0.3%CVE-2022-47653HIGHGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113EPSS 0.3%CVE-2021-33983HIGHBuffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the erEPSS 0.3%CVE-2024-57513MEDIUMA floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.EPSS 0.3%CVE-2026-24184HIGHNVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attackeEPSS 0.3%CVE-2024-50994MEDIUMNetgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipEPSS 0.3%CVE-2024-51002MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tEPSS 0.3%CVE-2024-52025MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2022-47664HIGHLibde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sseEPSS 0.3%CVE-2025-5601HIGHBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in WiresharkEPSS 0.3%CVE-2024-52029MEDIUMNetgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerabiliEPSS 0.3%CVE-2022-42431HIGHThis vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to exEPSS 0.3%CVE-2024-52028MEDIUMNetgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerabilityEPSS 0.3%CVE-2024-52023MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2024-52024MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2026-84126MEDIUMIncorrect boundary conditions in the Layout: Grid componentEPSS 0.3%CVE-2024-52026MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2026-32706HIGHPX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packetEPSS 0.3%CVE-2025-49458MEDIUMZoom Workplace Clients - Buffer OverflowEPSS 0.3%CVE-2025-52868LOWQsync CentralEPSS 0.3%