Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-45043LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45042LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45039LOWQTS, QuTS heroEPSS 0.6%CVE-2024-41209HIGHA heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code ExecuEPSS 0.6%CVE-2019-25741CRITICALMobatek MobaXterm 12.1 Buffer Overflow via Sessions FileEPSS 0.6%CVE-2023-0977MEDIUM A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page EPSS 0.6%CVE-2024-25394MEDIUMA buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' charaEPSS 0.6%CVE-2025-20222HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Buffer VulnerabilityEPSS 0.6%CVE-2024-40130CRITICALopen5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.EPSS 0.6%CVE-2023-22399HIGHJunos OS: QFX10K Series: PFE crash upon receipt of specific genuine packets when sFlow is enabledEPSS 0.6%CVE-2026-34956MEDIUMOpenvswitch: open vswitch: denial of service via malformed ftp epasv commandEPSS 0.6%CVE-2025-22904CRITICALRE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.EPSS 0.6%CVE-2025-22916CRITICALRE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.EPSS 0.6%CVE-2025-22907CRITICALRE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.EPSS 0.6%CVE-2024-34252HIGHwasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupiEPSS 0.6%CVE-2025-25456CRITICALTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.EPSS 0.6%CVE-2025-46035HIGHBuffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTEPSS 0.6%CVE-2023-46256MEDIUMPX4-Autopilot Heap Buffer Overflow BugEPSS 0.6%CVE-2026-52189HIGHBuffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the goheaEPSS 0.6%CVE-2026-20911CRITICALA heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A speEPSS 0.6%