Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-43573MEDIUMA buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackerEPSS 0.2%CVE-2023-43581MEDIUMA buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2023-5075MEDIUMA buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevatedEPSS 0.2%CVE-2023-43569MEDIUMA buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegesEPSS 0.2%CVE-2023-3494—bhyve privileged guest escape via fwctlEPSS 0.2%CVE-2024-35419MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackeEPSS 0.2%CVE-2025-44952HIGHA missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a EPSS 0.2%CVE-2024-33876MEDIUMHDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.EPSS 0.2%CVE-2022-40137MEDIUMA buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arEPSS 0.2%CVE-2024-35420MEDIUMwac commit 385e1 was discovered to contain a heap overflow.EPSS 0.2%CVE-2024-35418MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackerEPSS 0.2%CVE-2020-37166MEDIUMAbsoluteTelnet 11.12 - 'SSH2/username' Denial of ServiceEPSS 0.2%CVE-2024-33875MEDIUMHDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruEPSS 0.2%CVE-2022-29210MEDIUMHeap buffer overflow due to incorrect hash function in TensorFlowEPSS 0.2%CVE-2020-37036HIGHRM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer OverflowEPSS 0.2%CVE-2024-48424MEDIUMA heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specificalEPSS 0.2%CVE-2020-37049HIGHFrigate 3.36.0.9 - 'Command Line' Local Buffer OverflowEPSS 0.2%CVE-2024-26785MEDIUMiommufd: Fix protection fault in iommufd_test_syz_conv_iovaEPSS 0.2%CVE-2021-47172MEDIUMiio: adc: ad7124: Fix potential overflow due to non sequential channel numbersEPSS 0.2%CVE-2025-44951HIGHA missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a locEPSS 0.2%