Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2025-4160MEDIUMPCMan FTP Server LS Command buffer overflowEPSS 0.7%CVE-2025-4792MEDIUMFreeFloat FTP Server MDELETE Command buffer overflowEPSS 0.7%CVE-2025-4161MEDIUMPCMan FTP Server VERBOSE Command buffer overflowEPSS 0.7%CVE-2025-5076MEDIUMFreeFloat FTP Server SEND Command buffer overflowEPSS 0.7%CVE-2025-5049MEDIUMFreeFloat FTP Server APPEND Command buffer overflowEPSS 0.7%CVE-2025-5112MEDIUMFreeFloat FTP Server MGET Command buffer overflowEPSS 0.7%CVE-2025-5050MEDIUMFreeFloat FTP Server BELL Command buffer overflowEPSS 0.7%CVE-2025-5111MEDIUMFreeFloat FTP Server TYPE Command buffer overflowEPSS 0.7%CVE-2025-4159MEDIUMPCMan FTP Server GLOB Command buffer overflowEPSS 0.7%CVE-2026-75124HIGHPLANET GS-4210-16P2S V3 Memory Corruption via dispatcher.cgi _readHttpParamEPSS 0.7%CVE-2024-48150CRITICALD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.EPSS 0.7%CVE-2025-24157MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VEPSS 0.7%CVE-2025-5220MEDIUMFreeFloat FTP Server GET Command buffer overflowEPSS 0.7%CVE-2024-38952HIGHPX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.EPSS 0.7%CVE-2026-24660HIGHA heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted maliciEPSS 0.7%CVE-2023-36358HIGHTP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /EPSS 0.7%CVE-2025-5075MEDIUMFreeFloat FTP Server DEBUG Command buffer overflowEPSS 0.7%CVE-2025-13553HIGHD-Link DWR-M920 formPinManageSetup sub_41C7FC buffer overflowEPSS 0.7%CVE-2025-15215HIGHTenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflowEPSS 0.7%CVE-2026-51380CRITICALBuffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or poteEPSS 0.7%