Weaknesses of type CWE-120

3,167 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2026-58552MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2026-58551MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2025-36924HIGHIn ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This EPSS 0.1%CVE-2022-33277HIGHBuffer copy without checking size of input in modemEPSS 0.1%CVE-2022-33278HIGHBuffer copy without checking the size of input in HLOSEPSS 0.1%CVE-2022-25655HIGHBuffer copy without checking the size of input in WLAN HAL.EPSS 0.1%CVE-2022-25724HIGHMemory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2023-33030CRITICALBuffer Copy without Checking Size of Input in HLOSEPSS 0.1%CVE-2024-23375MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in RILEPSS 0.1%CVE-2023-24284LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.EPSS 0.1%CVE-2022-39121MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39122MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2023-24291LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.EPSS 0.1%CVE-2023-24287LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.EPSS 0.1%CVE-2023-24285LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long movEPSS 0.1%CVE-2022-39120MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-33217HIGHMemory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernEPSS 0.1%CVE-2025-20149MEDIUMA vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affectedEPSS 0.1%CVE-2022-42760MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-8412LOWVMDP: Potential buffer overflow in the RtlQueryRegistryValues functionEPSS 0.1%