Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2026-15484HIGHTRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflowEPSS 0.8%CVE-2026-6630HIGHTenda F451 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflowEPSS 0.8%CVE-2026-4488HIGHUTT HiPER 1250GW setSysAdm strcpy buffer overflowEPSS 0.8%CVE-2026-7748HIGHTotolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflowEPSS 0.8%CVE-2026-7513HIGHUTT HiPER 1200GW formRemoteControl strcpy buffer overflowEPSS 0.8%CVE-2026-4487HIGHUTT HiPER 1200GW websHostFilter strcpy buffer overflowEPSS 0.8%CVE-2026-7503HIGHcode-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflowEPSS 0.8%CVE-2026-5566HIGHUTT HiPER 1250GW formNatStaticMap strcpy buffer overflowEPSS 0.8%CVE-2026-7717HIGHTotolink WA300 POST Request cstecgi.cgi UploadCustomModule buffer overflowEPSS 0.8%CVE-2026-8137HIGHTotolink X5000R formDdns sub_458E40 buffer overflowEPSS 0.8%CVE-2026-1162CRITICALUTT HiPER 810 setSysAdm strcpy buffer overflowEPSS 0.8%CVE-2025-13548HIGHD-Link DIR-822K/DWR-M920 formFirewallAdv buffer overflowEPSS 0.8%CVE-2025-15193HIGHD-Link DWR-M920 formParentControl sub_423848 buffer overflowEPSS 0.8%CVE-2025-15189HIGHD-Link DWR-M920 formDefRoute sub_464794 buffer overflowEPSS 0.8%CVE-2022-36280MEDIUMThere is an out-of-bounds write vulnerability in vmwgfx driverEPSS 0.8%CVE-2025-8760CRITICALINSTAR 2K+/4K fcgi_server base64_decode buffer overflowEPSS 0.8%CVE-2025-15431HIGHUTT 进取 512W formFtpServerDirConfig strcpy buffer overflowEPSS 0.8%CVE-2025-15430HIGHUTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflowEPSS 0.8%CVE-2026-64767CRITICALA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.8%CVE-2026-55209CRITICALresdata insufficiently validates untrusted GRDECL filesEPSS 0.8%