Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-11295HIGHBelkin F9K1015 formPPPoESetup buffer overflowEPSS 1.1%CVE-2025-29047CRITICALBuffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddEPSS 1.1%CVE-2025-29044CRITICALBuffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key vEPSS 1.1%CVE-2025-29045CRITICALBuffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key valueEPSS 1.1%CVE-2025-29046CRITICALBuffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSEPSS 1.1%CVE-2025-11302HIGHBelkin F9K1015 formWpsStart buffer overflowEPSS 1.1%CVE-2025-11301HIGHBelkin F9K1015 formWlanSetupWPS buffer overflowEPSS 1.1%CVE-2025-11293HIGHBelkin F9K1015 formConnectionSetting buffer overflowEPSS 1.1%CVE-2025-11297HIGHBelkin F9K1015 formSetLanguage buffer overflowEPSS 1.1%CVE-2025-10170HIGHUTT 1200GW formApLbConfig sub_4B48F8 buffer overflowEPSS 1.1%CVE-2025-10172HIGHUTT 750W formPictureUrl buffer overflowEPSS 1.1%CVE-2025-10171HIGHUTT 1250GW formConfigApConfTemp sub_453DC buffer overflowEPSS 1.1%CVE-2020-5214MEDIUMNetHack error recovery after syntax error in configuration file is subject to a buffer overflowEPSS 1.1%CVE-2020-5211MEDIUMNetHack AUTOCOMPLETE configuration file option is subject to a buffer overflowEPSS 1.1%CVE-2026-0839HIGHUTT 进取 520W APSecurity strcpy buffer overflowEPSS 1.1%CVE-2025-10757HIGHUTT 1200GW formConfigDnsFilterGlobal buffer overflowEPSS 1.1%CVE-2023-22753HIGHUnauthenticated Buffer Overflow Vulnerabilities in ArubaOS ProcessesEPSS 1.1%CVE-2026-71958CRITICALD-Link DWR-M961 Buffer Overflow via quicksetup.cgiEPSS 1.1%CVE-2026-71957CRITICALD-Link DWR-M961 Buffer Overflow via app.cgiEPSS 1.1%CVE-2022-45995CRITICALThere is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to EPSS 1.1%