Weaknesses of type CWE-120

3,164 results

Estouro de buffer clássico

A aplicação copia dados para um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente, incluindo endereços de retorno ou ponteiros de função. Isso resulta na execução de código arbitrário com os privilégios da aplicação.

Example

Um programa lê uma entrada do usuário com gets() ou strcpy() sem limitar quantos bytes podem ser copiados. Um atacante fornece uma entrada maior que o buffer, sobrescrevendo a pilha e injetando código malicioso que será executado quando a função retornar.

How to mitigate

Use funções seguras que validam limites (strncpy, snprintf, fgets) e compile com proteções de pilha ativadas (-fstack-protector-all no GCC). Além disso, implemente validação de entrada no tamanho esperado e considere linguagens com gerenciamento automático de memória para novos projetos.

CVE-2024-6604HIGHMemory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13EPSS 0.5%CVE-2026-4687CRITICALSandbox escape due to incorrect boundary conditions in the Telemetry componentEPSS 0.5%CVE-2023-52946HIGHBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client beforEPSS 0.5%CVE-2023-52307HIGHStack overflow in paddle.linalg.lu_unpackEPSS 0.5%CVE-2024-22749HIGHGPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_wrEPSS 0.5%CVE-2018-1100—zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploEPSS 0.5%CVE-2024-23077HIGHJFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disEPSS 0.5%CVE-2024-27908MEDIUMA buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.EPSS 0.5%CVE-2023-47091HIGHAn issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10EPSS 0.5%CVE-2026-24112HIGHAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. WhenEPSS 0.5%CVE-2024-38951MEDIUMA buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.EPSS 0.5%CVE-2025-14196HIGHH3C Magic B1 aspForm sub_44de0 buffer overflowEPSS 0.5%CVE-2020-14354—A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. TEPSS 0.5%CVE-2022-20927HIGHA vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software EPSS 0.5%CVE-2023-33082CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HostEPSS 0.5%CVE-2023-33083CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HostEPSS 0.5%CVE-2024-34244HIGHlibmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed EPSS 0.5%CVE-2024-46558HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows EPSS 0.5%CVE-2024-46561HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows atEPSS 0.5%CVE-2020-21427HIGHBuffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary coEPSS 0.5%