Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2020-37191MEDIUMTop Password Software Dialup Password Recovery 1.30 - Denial of ServiceEPSS 0.3%CVE-2024-26927HIGHASoC: SOF: Add some bounds checking to firmware dataEPSS 0.3%CVE-2020-37180MEDIUMGTalk Password Finder 2.2.1 - 'Key' Denial of ServiceEPSS 0.3%CVE-2024-6198HIGHSNORE Interface Unauthenticated Remote Code ExecutionEPSS 0.3%CVE-2020-37211MEDIUMSpotIM 2.2 - 'Name' Denial Of ServiceEPSS 0.3%CVE-2020-37210MEDIUMSpotIE 2.9.5 - 'Key' Denial of ServiceEPSS 0.3%CVE-2024-21463HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.3%CVE-2024-21480HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.3%CVE-2026-73774HIGHUnauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CXEPSS 0.3%CVE-2020-37212MEDIUMSpotMSN 2.4.6 - 'Name' Denial of ServiceEPSS 0.3%CVE-2023-6238MEDIUMKernel: nvme: memory corruption via unprivileged user passthroughEPSS 0.3%CVE-2025-27835HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.EPSS 0.3%CVE-2024-53426MEDIUMA heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.EPSS 0.3%CVE-2026-73772MEDIUMUnauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CXEPSS 0.3%CVE-2024-52066HIGHPotential stack corruption in Routing Service when using a malicious XML configuration documentEPSS 0.3%CVE-2021-29612LOWHeap buffer overflow in `BandedTriangularSolve`EPSS 0.3%CVE-2026-22627HIGHA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 maEPSS 0.3%CVE-2025-8177MEDIUMLibTIFF thumbnail.c setrow buffer overflowEPSS 0.3%CVE-2024-25196LOWOpen Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controllEPSS 0.3%CVE-2020-36940MEDIUMEasy CD & DVD Cover Creator 4.13 - Denial of ServiceEPSS 0.3%