Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-29338MEDIUMNXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the EPSS 0.2%CVE-2020-37028HIGHSocusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer OverflowEPSS 0.2%CVE-2023-29414HIGH A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalaEPSS 0.2%CVE-2020-37029HIGHFTPDummy 4.80 - Local Buffer OverflowEPSS 0.2%CVE-2018-25366HIGHCuteFTP 5.0 XP Buffer Overflow via Site Manager Label FieldEPSS 0.2%CVE-2020-37025HIGHPort Forwarding Wizard 4.8.0 - Buffer OverflowEPSS 0.2%CVE-2018-25376HIGHSocusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEHEPSS 0.2%CVE-2020-37024HIGHNidesoft DVD Ripper 5.2.18 - Local Buffer OverflowEPSS 0.2%CVE-2024-25724HIGHIn RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, QueuEPSS 0.2%CVE-2021-37650HIGHSegfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlowEPSS 0.2%CVE-2018-25284MEDIUMHD Tune Pro 5.70 Denial of Service via Options DialogEPSS 0.2%CVE-2018-25377HIGHFlash Slideshow Maker Professional 5.20 Buffer Overflow SEHEPSS 0.2%CVE-2023-50821MEDIUMA vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versioEPSS 0.2%CVE-2024-45184MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 210EPSS 0.2%CVE-2024-44306HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to executeEPSS 0.2%CVE-2024-44307HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to executeEPSS 0.2%CVE-2022-45126MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.EPSS 0.2%CVE-2022-43662MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.EPSS 0.2%CVE-2025-27071HIGHBuffer Copy Without Checking Size of Input in Powerline Communication FirmwareEPSS 0.2%CVE-2025-59969HIGHJunos OS Evolved: QFX5000 Series and PTX Series: An attacker sending crafted multicast packets will cause evo-aftmand / evo-pfemand to crash and restartEPSS 0.2%