Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-46001MEDIUMBuffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via theEPSS 0.3%CVE-2025-53711MEDIUMTP-Link TL-WR841N, TL-WR842ND and TL-WR949N WlanNetworkRpm.htm buffer overflowEPSS 0.3%CVE-2025-53712MEDIUMTP-Link TL-WR841N WlanNetworkRpm_AP.htm buffer overflowEPSS 0.3%CVE-2025-53713MEDIUMTP-Link TL-WR841N WlanNetworkRpm_APC.htm buffer overflowEPSS 0.3%CVE-2023-28904MEDIUMBypass of secure boot processEPSS 0.3%CVE-2023-21406HIGHHeap-based buffer overflow in Axis A1001 Network Door Controller's OSDP communicationEPSS 0.3%CVE-2025-20709HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2023-0996HIGH There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this throuEPSS 0.3%CVE-2025-33131MEDIUMFixes to common vulnerabilities found in IBM Db2 High Performance UnloadEPSS 0.3%CVE-2025-1786MEDIUMrizinorg rizin pdb.c msf_stream_directory_free buffer overflowEPSS 0.3%CVE-2026-20644MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.3%CVE-2025-32089HIGHDell ControlVault3 CvManager_SBI buffer overflow vulnerabilityEPSS 0.3%CVE-2026-20635MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.3%CVE-2026-0110CRITICALIn MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilEPSS 0.3%CVE-2026-16364CRITICALIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.3%CVE-2024-53425MEDIUMA heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processingEPSS 0.3%CVE-2024-51020MEDIUMNetgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the apn parameter at usbISP_detail_edit.cgi. This vulnerability allEPSS 0.3%CVE-2024-51016MEDIUMNetgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allowsEPSS 0.3%CVE-2024-52015MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptEPSS 0.3%CVE-2024-51004MEDIUMNetgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi viEPSS 0.3%