Weaknesses of type CWE-120

3,166 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-27834HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document tEPSS 0.3%CVE-2026-92043HIGHPrivilege escalation due to incorrect boundary conditions in the Audio/Video componentEPSS 0.3%CVE-2026-92014HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2024-32324HIGHBuffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code EPSS 0.3%CVE-2022-47090HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check EPSS 0.3%CVE-2022-42271HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2022-42274HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2024-58106MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58110MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58109MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58108MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-56557HIGHiio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xferEPSS 0.3%CVE-2024-31963MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.3%CVE-2024-35422HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2023-52364MEDIUMVulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may EPSS 0.3%CVE-2026-18280LOWSony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2024-12194HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-53335HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.EPSS 0.3%CVE-2026-1108MEDIUMcijliu librtsp rtsp_rely_dumps buffer overflowEPSS 0.2%CVE-2024-26797HIGHdrm/amd/display: Prevent potential buffer overflow in map_hw_resourcesEPSS 0.2%