Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2022-4172MEDIUMAn integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_ersEPSS 0.4%CVE-2025-28025HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 werEPSS 0.4%CVE-2025-28020HIGHTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.EPSS 0.4%CVE-2025-52870LOWQsync CentralEPSS 0.4%CVE-2025-48723LOWQsync CentralEPSS 0.4%CVE-2025-14310CRITICALBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects rethinkdb: before 2.4.4EPSS 0.4%CVE-2025-28021HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 pEPSS 0.4%CVE-2024-4640HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmailEPSS 0.4%CVE-2025-28028HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 werEPSS 0.4%CVE-2025-28022HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.EPSS 0.4%CVE-2025-48724LOWQsync CentralEPSS 0.4%CVE-2024-37040MEDIUMCWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to EPSS 0.4%CVE-2025-26240HIGHIn JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server applicatioEPSS 0.4%CVE-2023-51367MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-34106HIGHPDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image FeatureEPSS 0.4%CVE-2024-48712MEDIUMIn TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overfEPSS 0.4%CVE-2024-50839MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0.EPSS 0.4%CVE-2025-52221HIGHTenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameterEPSS 0.4%CVE-2024-10559MEDIUMSourceCodester Airport Booking Management System details buffer overflowEPSS 0.4%CVE-2023-33025CRITICALBuffer Copy without Checking Size of Input in Data ModemEPSS 0.4%