Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-25662CRITICALTenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via theEPSS 0.4%CVE-2024-46581HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows aEPSS 0.4%CVE-2025-25678CRITICALTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.EPSS 0.4%CVE-2024-46584HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allEPSS 0.4%CVE-2024-46595HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows EPSS 0.4%CVE-2024-46588HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allowEPSS 0.4%CVE-2025-25674CRITICALTenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.EPSS 0.4%CVE-2024-53320CRITICALQualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProjEPSS 0.4%CVE-2023-4452MEDIUMWeb Server Buffer Overflow VulnerabilityEPSS 0.4%CVE-2026-7321CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC: Networking componentEPSS 0.4%CVE-2026-32741HIGHlibheif has a heap buffer overflow in decode_mask_image()EPSS 0.4%CVE-2023-39388—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause homEPSS 0.4%CVE-2023-39389—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause homEPSS 0.4%CVE-2023-39063HIGHBuffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the StepEPSS 0.4%CVE-2023-39408—DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.EPSS 0.4%CVE-2025-69720HIGHThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.EPSS 0.4%CVE-2023-39386—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newEPSS 0.4%CVE-2025-51281HIGHD-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability alEPSS 0.4%CVE-2024-40536MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the conEPSS 0.4%CVE-2024-50697HIGHIn SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not haEPSS 0.4%