Weaknesses of type CWE-120

3,168 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-36928HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalaEPSS 0.1%CVE-2025-36930HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2025-36927HIGHIn GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. This could lead to lEPSS 0.1%CVE-2025-21426MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2023-21135—In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validatiEPSS 0.1%CVE-2025-27043HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.1%CVE-2025-27052HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2025-27058HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2022-48439MEDIUMIn cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2024-53013MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2024-25984MEDIUMIn dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local inforEPSS 0.1%CVE-2022-47487MEDIUMIn thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local EPSS 0.1%CVE-2026-55290LOWIn setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local informatiEPSS 0.1%CVE-2025-21445HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2025-21444HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2024-27225MEDIUMIn sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informEPSS 0.1%CVE-2025-21476HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2025-47341HIGHBuffer Copy Without Checking Size of Input in CameraEPSS 0.1%CVE-2023-52346MEDIUMIn modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with SysEPSS 0.1%CVE-2025-27072MEDIUMBuffer Copy Without Checking Size of Input in Automotive Vehicle NetworksEPSS 0.1%