Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2024-57471CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing funEPSS 0.8%CVE-2025-14526HIGHTenda CH22 L7Im frmL7ImForm buffer overflowEPSS 0.8%CVE-2026-15314HIGHAuthenticated Denial-of-Service Vulnerability in TP-Link Tapo P110EPSS 0.8%CVE-2023-50361MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2024-0762HIGHPotential buffer overflow when handling UEFI variablesEPSS 0.8%CVE-2025-6882HIGHD-Link DIR-513 formSetWanPPTP buffer overflowEPSS 0.8%CVE-2025-43213MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOEPSS 0.8%CVE-2023-38671HIGHHeap buffer overflow in paddle.traceEPSS 0.8%CVE-2025-13551HIGHD-Link DIR-822K/DWR-M920 formWanConfigSetup buffer overflowEPSS 0.8%CVE-2026-1140HIGHUTT 进取 520W ConfigExceptAli strcpy buffer overflowEPSS 0.8%CVE-2025-13552HIGHD-Link DIR-822K/DWR-M920 formWlEncrypt buffer overflowEPSS 0.8%CVE-2026-30652HIGHA remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras runniEPSS 0.8%CVE-2025-13550HIGHD-Link DIR-822K/DWR-M920 formVpnConfigSetup buffer overflowEPSS 0.8%CVE-2010-10016CRITICALBS.Player 2.57 Buffer Overflow via M3U Playlist ImportEPSS 0.8%CVE-2026-76691HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API EndpointEPSS 0.8%CVE-2026-10126HIGHEdimax BR-6478AC POST Request formQoS buffer overflowEPSS 0.8%CVE-2026-44880HIGHLow-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%CVE-2024-20451HIGHMultiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA5EPSS 0.8%CVE-2026-27820LOWzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionEPSS 0.8%CVE-2025-11323HIGHUTT 1250GW formUserStatusRemark strcpy buffer overflowEPSS 0.8%