Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-32722CRITICALStack-buffer Overflow in library module zbxjsonEPSS 0.7%CVE-2026-2066HIGHUTT 进取 520W formIpGroupConfig strcpy buffer overflowEPSS 0.7%CVE-2026-76682HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.7%CVE-2026-2071HIGHUTT 进取 520W formP2PLimitConfig strcpy buffer overflowEPSS 0.7%CVE-2024-55194CRITICALOpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.EPSS 0.7%CVE-2026-2070HIGHUTT 进取 520W formPolicyRouteConf strcpy buffer overflowEPSS 0.7%CVE-2024-27128MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-27129MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2023-28116HIGHBuffer overflow in L2CAP due to misconfigured MTUEPSS 0.7%CVE-2025-12345HIGHLLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflowEPSS 0.7%CVE-2026-18279HIGHSony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-44331HIGHIncorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of servicEPSS 0.7%CVE-2023-40830CRITICALTenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.EPSS 0.7%CVE-2022-44232HIGHlibming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a diffeEPSS 0.7%CVE-2026-71941HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmailEPSS 0.7%CVE-2025-12611HIGHTenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflowEPSS 0.7%CVE-2026-71942HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalertEPSS 0.7%CVE-2026-71938HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrpEPSS 0.7%CVE-2026-71935HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupActionEPSS 0.7%CVE-2026-71934HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via pingtraceEPSS 0.7%