Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-26889MEDIUMBluetooth: hci_core: Fix possible buffer overflowEPSS 0.3%CVE-2025-1277HIGHPDF File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-30164MEDIUMAmazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissioEPSS 0.3%CVE-2023-42757MEDIUMProcess Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executaEPSS 0.3%CVE-2024-50956MEDIUMA buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLCEPSS 0.3%CVE-2025-9390MEDIUMvim xxd xxd.c main buffer overflowEPSS 0.3%CVE-2023-52365HIGHOut-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features tEPSS 0.3%CVE-2023-4163MEDIUMPossible buffer overflow in portcfgfportbuffers in Brocade Fabric OSEPSS 0.3%CVE-2024-53589HIGHGNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.EPSS 0.3%CVE-2026-0136HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2025-25610HIGHTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation EPSS 0.3%CVE-2025-25609HIGHTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation EPSS 0.3%CVE-2024-6350MEDIUMEmberZNet malformed MAC layer packet leads to denial of serviceEPSS 0.3%CVE-2026-0144HIGHIn writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote deEPSS 0.3%CVE-2026-3870MEDIUMA buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could EPSS 0.3%CVE-2026-3871MEDIUMA buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 couEPSS 0.3%CVE-2024-25817HIGHBuffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, aEPSS 0.3%CVE-2026-42808MEDIUMAn issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{coines_read_stream_seEPSS 0.3%CVE-2024-41176HIGHBeckhoff: Local Denial of Service issue in package MDP included in TwinCAT/BSDEPSS 0.3%CVE-2025-51823MEDIUMlibcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function usEPSS 0.3%