Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-27407HIGHfs/ntfs3: Fixed overflow check in mi_enum_attr()EPSS 0.3%CVE-2020-36940MEDIUMEasy CD & DVD Cover Creator 4.13 - Denial of ServiceEPSS 0.3%CVE-2021-25497HIGHA possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61EPSS 0.3%CVE-2021-25496HIGHA possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61EPSS 0.3%CVE-2021-25498HIGHA possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.EPSS 0.3%CVE-2026-20100HIGHA vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwEPSS 0.3%CVE-2024-28570MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the pEPSS 0.3%CVE-2024-40724HIGHHeap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a EPSS 0.3%CVE-2024-50664HIGHgpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.EPSS 0.3%CVE-2024-28576MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the oEPSS 0.3%CVE-2025-10886HIGHMODEL File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2025-29625HIGHA buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overlEPSS 0.3%CVE-2026-0146HIGHIn mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This coulEPSS 0.3%CVE-2026-0147HIGHIn __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. ThiEPSS 0.3%CVE-2023-34115MEDIUMBuffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a deniaEPSS 0.3%CVE-2023-31979HIGHCatdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.EPSS 0.3%CVE-2026-0126HIGHIn WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additioEPSS 0.3%CVE-2026-92010HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92012HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2023-31431MEDIUMA buffer overflow vulnerability in “diagstatus” commandEPSS 0.3%