Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2026-92009HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92008HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2023-31431MEDIUMA buffer overflow vulnerability in “diagstatus” commandEPSS 0.3%CVE-2026-92013HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92011HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92007HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92010HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2025-43532LOWA memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPaEPSS 0.3%CVE-2026-25506HIGHMUNGE has a buffer overflow in message unpacking allows key leakage and credential forgeryEPSS 0.3%CVE-2026-31060MEDIUMUTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the formGroupConfig functionEPSS 0.3%CVE-2025-36553HIGHDell ControlVault3 CvManager buffer overflow vulnerabilityEPSS 0.3%CVE-2026-31065MEDIUMUTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formConfigCliForEngineerOEPSS 0.3%CVE-2026-31061MEDIUMUTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ConfigAdvideo functiEPSS 0.3%CVE-2026-31066MEDIUMUTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit functEPSS 0.3%CVE-2026-31063MEDIUMUTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the formArpBindConfig functiEPSS 0.3%CVE-2026-31062MEDIUMUTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtpServerDirConfig funcEPSS 0.3%CVE-2026-31058MEDIUMUTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilEPSS 0.3%CVE-2024-50282HIGHdrm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()EPSS 0.3%CVE-2025-2017HIGHAshlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-44175MEDIUMTenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.EPSS 0.3%