Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2015-0843CRITICALyubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.EPSS 0.4%CVE-2026-84520CRITICALA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to EPSS 0.4%CVE-2026-12246HIGHOut of bounds stack write with crafted APL RREPSS 0.4%CVE-2024-34057HIGHTriangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. TheEPSS 0.4%CVE-2026-76651MEDIUMPre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841NEPSS 0.4%CVE-2023-28561CRITICALBuffer Copy Without Checking Size of Input in QESLEPSS 0.4%CVE-2025-26008CRITICALIn Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHosEPSS 0.4%CVE-2025-26004CRITICALTelesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDEPSS 0.4%CVE-2023-54328MEDIUMAimOne Video Converter 2.04 Build 103 Buffer Overflow in Registration FormEPSS 0.4%CVE-2025-26007CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.EPSS 0.4%CVE-2025-26011CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePasswoEPSS 0.4%CVE-2026-6730CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.4%CVE-2025-26005CRITICALTelesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.EPSS 0.4%CVE-2025-26006CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.EPSS 0.4%CVE-2023-50268MEDIUMjq has stack-based buffer overflow in decNaNsEPSS 0.4%CVE-2023-28582CRITICALBuffer Copy Without Checking Size of Input in Data ModemEPSS 0.4%CVE-2023-6881HIGHfs: fuse: buffer overflow vulnerability in the Zephyr FSEPSS 0.4%CVE-2026-28934MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe EPSS 0.4%CVE-2023-38583HIGHA stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2025-55599CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.EPSS 0.4%