Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-28213HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28215HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28211HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28214HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-32356HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28212HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28210HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2020-37171MEDIUMTapinRadio 2.12.3 - 'username' Denial of ServiceEPSS 0.2%CVE-2024-53192HIGHclk: clk-loongson2: Fix potential buffer overflow in flexible-array member accessEPSS 0.2%CVE-2024-6351MEDIUMMalformed packet leads to denial of service in NWK/APS layerEPSS 0.2%CVE-2025-64182MEDIUMOpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()EPSS 0.2%CVE-2020-37170MEDIUMTapinRadio 2.12.3 - 'address' Denial of ServiceEPSS 0.2%CVE-2024-6352MEDIUMMalformed packet leads to denial of service in APS layerEPSS 0.2%CVE-2023-27956MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iEPSS 0.2%CVE-2020-37131MEDIUMProduct Key Explorer 4.2.2.0 - 'Key' Denial of ServiceEPSS 0.2%CVE-2025-29476MEDIUMBuffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0EPSS 0.2%CVE-2024-29645HIGHBuffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.EPSS 0.2%CVE-2024-48425MEDIUMA segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library duriEPSS 0.2%CVE-2026-0849LOWcrypto: ATAES132A response length allows stack buffer overflowEPSS 0.2%CVE-2020-37215MEDIUMMSN Password Recovery 1.30 - Denial of ServiceEPSS 0.2%