Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2026-34124HIGHDenial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WSEPSS 0.4%CVE-2025-50401CRITICALMercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.EPSS 0.4%CVE-2026-9625HIGHRSLinx Classic® - Multiple VulnerabilitiesEPSS 0.4%CVE-2025-12011CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%CVE-2024-51409MEDIUMBuffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed foEPSS 0.4%CVE-2025-12012CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%CVE-2026-54257CRITICALElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowEPSS 0.4%CVE-2023-28562CRITICALBuffer Copy Without Checking Size of Input in QESLEPSS 0.4%CVE-2025-50258HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.EPSS 0.4%CVE-2025-50263HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.EPSS 0.4%CVE-2023-2597HIGHIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size oEPSS 0.4%CVE-2026-39869MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.4%CVE-2024-33809MEDIUMPingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service atEPSS 0.4%CVE-2019-10882MEDIUMNetskope client buffer overflow vulnerabilityEPSS 0.4%CVE-2024-57544MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stackEPSS 0.4%CVE-2026-24110CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addEPSS 0.4%CVE-2025-43520MEDIUMA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPaEPSS 0.4%KEVCVE-2024-57545MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the EPSS 0.4%CVE-2026-24103CRITICALA buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.EPSS 0.4%CVE-2023-5139MEDIUMPotential buffer overflow vulnerability in the Zephyr STM32 Crypto driverEPSS 0.4%