Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-50997MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptEPSS 0.4%CVE-2024-50996MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpaEPSS 0.4%CVE-2026-19002HIGHCrafted database metadata may cause memory corruption in MongoDB BI Connector ODBC DriverEPSS 0.4%CVE-2025-2851HIGHGL.iNet GL-A1300 Slate Plus RPC plugins.so buffer overflowEPSS 0.4%CVE-2025-50641MEDIUMTenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.EPSS 0.4%CVE-2023-1452MEDIUMGPAC load_text.c buffer overflowEPSS 0.4%CVE-2025-24956MEDIUMA vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsiEPSS 0.4%CVE-2026-57274HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-57277HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-57273HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-57278HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-57276HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-57275HIGHGeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityEPSS 0.4%CVE-2026-84571MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, vEPSS 0.4%CVE-2021-33973HIGHBuffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges.EPSS 0.4%CVE-2025-63679CRITICALfree5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, theEPSS 0.4%CVE-2024-25076MEDIUMAn issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validatingEPSS 0.4%CVE-2020-37205MEDIUMRemShutdown 2.9.0.0 - 'Name' Denial of ServiceEPSS 0.4%CVE-2025-69807HIGHp2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of serviceEPSS 0.4%CVE-2020-37204MEDIUMRemShutdown 2.9.0.0 - 'Key' Denial of ServiceEPSS 0.4%