Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2018-25423MEDIUMArm Whois 3.11 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2023-28570MEDIUMBuffer Copy without Checking Size of Input in AudioEPSS 0.1%CVE-2020-8941MEDIUMUnchecked buffer overrun in enc_untrusted_inet_ptonEPSS 0.1%CVE-2018-25323HIGHAllok AVI DivX MPEG to DVD Converter 2.6.1217 Buffer Overflow SEHEPSS 0.1%CVE-2024-56452MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2018-25288MEDIUMStyleWriter 1.0 Denial of Service via Pattern InputEPSS 0.1%CVE-2018-25293MEDIUMPrime95 29.4b7 Denial of Service via Proxy Password FieldEPSS 0.1%CVE-2018-25292MEDIUMBome Restorator 1793 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2018-25289MEDIUMSoftdisk 3.0.3 Buffer Overflow Denial of ServiceEPSS 0.1%CVE-2018-25277MEDIUMPixGPS 1.1.8 Buffer Overflow Denial of ServiceEPSS 0.1%CVE-2018-25286MEDIUMEasy PhotoResQ 1.0 Buffer Overflow Denial of ServiceEPSS 0.1%CVE-2026-5404MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in WiresharkEPSS 0.1%CVE-2018-25275MEDIUMFaleemi Plus 1.0.2 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2018-25291MEDIUMProject64 2.3.2 Denial of Service via Plugin DirectoryEPSS 0.1%CVE-2020-8940MEDIUMUnchecked buffer overrun in enc_untrusted_recvmsgEPSS 0.1%CVE-2020-8942MEDIUMUnchecked buffer overrun in enc_untrusted_readEPSS 0.1%CVE-2026-24799MEDIUMA heap-based buffer over-read or buffer overflow in davisking/dlibEPSS 0.1%CVE-2022-42756HIGHIn sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2020-8943MEDIUMUnchecked buffer overrun in enc_untrusted_recvfromEPSS 0.1%CVE-2026-19568HIGHSVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds MaxEPSS 0.1%