Weaknesses of type CWE-120

3,166 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2024-52014MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptEPSS 0.3%CVE-2024-51000MEDIUMNetgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmEPSS 0.3%CVE-2025-27830HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for bEPSS 0.3%CVE-2025-25510MEDIUMTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.EPSS 0.3%CVE-2024-32389LOWBuffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiEPSS 0.3%CVE-2026-6384HIGHGimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processingEPSS 0.3%CVE-2025-25505MEDIUMTenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.EPSS 0.3%CVE-2026-2034HIGHSante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-36917MEDIUMIn SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This could lead to remotEPSS 0.3%CVE-2024-44218HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia EPSS 0.3%CVE-2023-34140MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 EPSS 0.3%CVE-2024-44144MEDIUMA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, maEPSS 0.3%CVE-2024-56914MEDIUMD-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.EPSS 0.3%CVE-2026-1110MEDIUMcijliu librtsp rtsp_parse_method buffer overflowEPSS 0.3%CVE-2026-24800CRITICALA heap-based buffer over-read or buffer overflow in tildearrow/furnaceEPSS 0.3%CVE-2026-10275LOWOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflowEPSS 0.3%CVE-2024-53027HIGHBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.3%CVE-2026-55343HIGHIn decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote coEPSS 0.3%CVE-2026-83596HIGHWebkitgtk: validate the full featurelist array once in opentypeverticaldata findfeatureEPSS 0.3%CVE-2020-37180MEDIUMGTalk Password Finder 2.2.1 - 'Key' Denial of ServiceEPSS 0.3%