Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-55611CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.EPSS 0.4%CVE-2021-46882HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-34055HIGHjhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.EPSS 0.4%CVE-2021-46884HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2024-28565MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the pEPSS 0.4%CVE-2021-46883HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2022-48497—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46885HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-46881HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2025-48721LOWQTS, QuTS heroEPSS 0.4%CVE-2021-46886HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2022-48501HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-48490—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2025-1368MEDIUMMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflowEPSS 0.4%CVE-2021-47798MEDIUMNoteBurner 2.35 - Denial Of Service (DoS) (PoC)EPSS 0.4%CVE-2024-57537MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack withoEPSS 0.4%CVE-2020-14374—A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffeEPSS 0.4%CVE-2024-25373MEDIUMTenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.EPSS 0.4%CVE-2024-22905HIGHBuffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSeEPSS 0.4%CVE-2025-12011CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%