Weaknesses of type CWE-120

3,168 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-29944MEDIUMA buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resultingEPSS 0.1%CVE-2026-56978HIGHIn get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2026-20782MEDIUMBuffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial oEPSS 0.1%CVE-2025-47389HIGHBuffer Copy Without Checking Size of Input in Automotive PlatformEPSS 0.1%CVE-2026-56892MEDIUMIn ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local informEPSS 0.1%CVE-2018-9402HIGHIn multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges iEPSS 0.1%CVE-2025-47399HIGHBuffer Copy Without Checking Size of Input in CameraEPSS 0.1%CVE-2026-49884HIGHIn rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esEPSS 0.1%CVE-2026-28580HIGHIn multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of prEPSS 0.1%CVE-2026-58695HIGHIn gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could EPSS 0.1%CVE-2022-47494MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-58839HIGHIn forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation ofEPSS 0.1%CVE-2022-47491MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47498MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47496MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47499MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-58823HIGHIn stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to locaEPSS 0.1%CVE-2022-47495MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47497MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2023-20624MEDIUMIn vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%