Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-50838MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. EPSS 0.5%CVE-2020-10023MEDIUMShell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trimEPSS 0.5%CVE-2025-66287HIGHWebkitgtk: processing maliciously crafted web content may lead to an unexpected process crashEPSS 0.5%CVE-2023-33045CRITICALBuffer Copy Without Checking Size of Input in WLAN FirmwareEPSS 0.5%CVE-2024-46431HIGHTenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerabEPSS 0.5%CVE-2023-27892LOWInsufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messagEPSS 0.5%CVE-2024-23968HIGHChargePoint Home Flex SrvrToSmSetAutoChnlListMsg Stack-based Buffer OverflowEPSS 0.5%CVE-2022-26528MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2022-26527MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2022-26529MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2026-19999MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2022-48260HIGHThere is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions.EPSS 0.5%CVE-2026-64691CRITICALA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpectEPSS 0.5%CVE-2025-28221HIGHTenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web serveEPSS 0.5%CVE-2025-28220HIGHTenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash EPSS 0.5%CVE-2025-50652HIGHAn issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.EPSS 0.5%CVE-2024-35400MEDIUMTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRulesEPSS 0.5%CVE-2020-21428LOWBuffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cauEPSS 0.5%CVE-2026-4729CRITICALMemory safety bugs fixed in Firefox 149 and Thunderbird 149EPSS 0.5%CVE-2026-10163HIGHEdimax BR-6478AC POST Request formUSBAccount buffer overflowEPSS 0.5%