Weaknesses of type CWE-120

3,169 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2018-9386MEDIUMIn reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could EPSS 0.1%CVE-2018-9403HIGHIn the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missingEPSS 0.1%CVE-2023-21143—In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could leEPSS 0.1%CVE-2022-47335MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47362MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47464MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47463MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47336MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2025-47335MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2025-47334MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2024-40659MEDIUMIn getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation featEPSS 0.1%CVE-2024-47032HIGHIn construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead toEPSS 0.1%CVE-2025-26434MEDIUMIn libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additioEPSS 0.1%CVE-2025-47321HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2017-13308MEDIUMIn tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validaEPSS 0.1%CVE-2025-31712MEDIUMIn cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no EPSS 0.1%CVE-2025-47394HIGHBuffer Copy Without Checking Size of Input in DSP ServiceEPSS 0.1%CVE-2025-47388HIGHBuffer Copy without Checking Size of Input in DSP ServiceEPSS 0.1%CVE-2025-36931HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2026-21382HIGHBuffer Copy Without Checking Size of Input in Power Management ICEPSS 0.1%