Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-51116HIGHTenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.EPSS 0.4%CVE-2025-50402CRITICALFAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.EPSS 0.4%CVE-2025-50398CRITICALMercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_passwordEPSS 0.4%CVE-2024-25115HIGHRedisBloom heap buffer overflow in CF.LOADCHUNK commandEPSS 0.4%CVE-2026-8093HIGHMemory safety bugs fixed in Firefox 150.0.2EPSS 0.4%CVE-2024-39129MEDIUMHeap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /sEPSS 0.4%CVE-2025-25900MEDIUMA buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.EPSS 0.4%CVE-2026-22184MEDIUMzlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()EPSS 0.4%CVE-2025-36525HIGHBIG-IP APM PingAccess Virtual Server VulnerabilityEPSS 0.4%CVE-2025-28018HIGHTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.EPSS 0.4%CVE-2022-25678CRITICALBuffer Copy Without Checking Size of Input in MODEMEPSS 0.4%CVE-2022-25740CRITICALBuffer Copy Without Checking Size of Input in MODEMEPSS 0.4%CVE-2025-25635HIGHTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation EPSS 0.4%CVE-2022-33259CRITICALBuffer copy without checking the size of input in ModemEPSS 0.4%CVE-2023-49556MEDIUMBuffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term functionEPSS 0.4%CVE-2024-41206MEDIUMA stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a craftedEPSS 0.4%CVE-2024-52017MEDIUMNetgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerabilEPSS 0.4%CVE-2025-50262HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.EPSS 0.4%CVE-2020-36995MEDIUMMocha Telnet Lite for iOS 4.2 - 'User' Denial of ServiceEPSS 0.4%CVE-2023-25664HIGHTensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad EPSS 0.4%