Weaknesses of type CWE-120

3,166 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-55499MEDIUMTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.EPSS 0.3%CVE-2023-43519HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in VideoEPSS 0.3%CVE-2026-82343MEDIUMGimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handlingEPSS 0.3%CVE-2023-43548HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.3%CVE-2025-51824MEDIUMlibcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.EPSS 0.3%CVE-2025-21780HIGHdrm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()EPSS 0.3%CVE-2018-9418HIGHIn handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to reEPSS 0.3%CVE-2024-48289MEDIUMAn issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via sEPSS 0.3%CVE-2024-43700HIGHxfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow EPSS 0.3%CVE-2021-3569—A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could resulEPSS 0.3%CVE-2023-27968HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.3%CVE-2025-10889HIGHCATPART File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-48806MEDIUMBuffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a craftEPSS 0.3%CVE-2022-42261HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may leaEPSS 0.3%CVE-2024-35410MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackersEPSS 0.3%CVE-2025-25453MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.EPSS 0.3%CVE-2025-25458MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.EPSS 0.3%CVE-2024-30799MEDIUMAn issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach REPSS 0.3%CVE-2025-27834HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document tEPSS 0.3%CVE-2025-43312MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.EPSS 0.3%