Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2021-34777MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-34776MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-34775MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2020-37188MEDIUMSpotOutlook 1.2.6 - 'Name' Denial of ServiceEPSS 0.4%CVE-2024-48416HIGHEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.EPSS 0.4%CVE-2020-37187MEDIUMSpotDialup 1.6.7 - 'Name' Denial of ServiceEPSS 0.4%CVE-2025-50673HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.aspEPSS 0.4%CVE-2025-23412HIGHBIG-IP APM access profile vulnerabilityEPSS 0.4%CVE-2025-50668HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endEPSS 0.4%CVE-2024-22526MEDIUMBuffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.EPSS 0.4%CVE-2024-52016MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilitEPSS 0.4%CVE-2025-60343HIGHMultiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.4%CVE-2025-65834CRITICALMeltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulEPSS 0.4%CVE-2025-60339HIGHMultiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of ServEPSS 0.4%CVE-2025-60340HIGHMultiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via EPSS 0.4%CVE-2024-5463MEDIUMA vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. EPSS 0.4%CVE-2024-53319HIGHA heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause Denial of Service (DoEPSS 0.4%CVE-2021-47813MEDIUMBackup Key Recovery 2.2.7 - Denial of Service (PoC)EPSS 0.4%CVE-2024-40083CRITICALA Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticEPSS 0.4%CVE-2021-47797MEDIUMLeawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)EPSS 0.4%