Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2023-52304HIGHStack overflow in paddle.searchsortedEPSS 0.6%CVE-2023-26318MEDIUMXiaomi router web interface post-authorization stack overflowEPSS 0.6%CVE-2023-41280MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-41292LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-45036LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-45035LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-41279MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2024-47864MEDIUMhome 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote EPSS 0.6%CVE-2023-45037LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2024-46045MEDIUMTenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.EPSS 0.6%CVE-2024-4143CRITICALCertain HP PC products using AMI BIOS – Buffer OverflowEPSS 0.6%CVE-2024-31040LOWBuffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial ofEPSS 0.6%CVE-2024-32763MEDIUMQTS, QuTS heroEPSS 0.6%CVE-2025-46785MEDIUMZoom Workplace Apps for Windows - Buffer Over-readEPSS 0.6%CVE-2026-20243HIGHClamAV ALZ Archive Processing Denial of Service VulnerabilityEPSS 0.6%CVE-2026-20217HIGHClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20244HIGHClamAV DMG File Processing Denial of Service VulnerabilityEPSS 0.6%CVE-2026-20213HIGHClamAV PE File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20214HIGHClamAV FSG File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20215HIGHClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%