Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2022-49040MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology DrivEPSS 0.2%CVE-2022-49041MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology DriEPSS 0.2%CVE-2025-0303HIGHLiteos_a has a buffer overflow vulnerabilityEPSS 0.2%CVE-2019-25326MEDIUMipPulse 1.92 - 'Enter Key' Denial of ServiceEPSS 0.2%CVE-2026-42450HIGHOpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parserEPSS 0.2%CVE-2026-64705MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS EPSS 0.2%CVE-2026-30006MEDIUMXnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.EPSS 0.2%CVE-2026-65357HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOEPSS 0.2%CVE-2026-84489MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, EPSS 0.2%CVE-2026-57246HIGHFoxit PDF Editor/Reader Signature Buffer Overflow VulnerabilityEPSS 0.2%CVE-2018-25369MEDIUMVisual Ping 0.8.0.0 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2025-1253MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-28841MEDIUMA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memoEPSS 0.2%CVE-2026-0157MEDIUMIn RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosurEPSS 0.2%CVE-2026-84577HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app maEPSS 0.2%CVE-2026-30981MEDIUMiccDEV has a heap-buffer-overflow read in CIccXmlArrayType<>EPSS 0.2%CVE-2018-25367MEDIUMNASA openVSP 3.16.1 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2026-43681HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-55277HIGHIn checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could leadEPSS 0.2%CVE-2024-52059MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.EPSS 0.2%