Weaknesses of type CWE-120

3,168 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-33031HIGHBuffer Copy Without Checking Size of Input in Automotive AudioEPSS 0.1%CVE-2023-28546HIGHBuffer Copy Without Checking Size of Input in SPS ApplicationsEPSS 0.1%CVE-2024-23378MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-28539MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.1%CVE-2023-43515MEDIUMBuffer copy without checking size of input (Classic buffer overflow) in HLOSEPSS 0.1%CVE-2021-43614MEDIUMVariableEditSmm: Error checking of UEFI variables could cause buffer overflow, leading to code executionEPSS 0.1%CVE-2023-33035HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2026-34866MEDIUMOut-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confiEPSS 0.1%CVE-2023-43526MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33068MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-43525MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-22384MEDIUMBuffer Copy Without Checking Size of Input in VR ServiceEPSS 0.1%CVE-2024-49829MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in CameraEPSS 0.1%CVE-2024-45541HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN Windows HostEPSS 0.1%CVE-2023-43524MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33069MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-33077MEDIUMBuffer Copy Without Checking Size of Input in HLOSEPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2024-56453MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2024-56456MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%