Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-55499MEDIUMTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.EPSS 0.3%CVE-2023-43519HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in VideoEPSS 0.3%CVE-2026-82343MEDIUMGimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handlingEPSS 0.3%CVE-2023-43548HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.3%CVE-2025-51824MEDIUMlibcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.EPSS 0.3%CVE-2025-21780HIGHdrm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()EPSS 0.3%CVE-2018-9418HIGHIn handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to reEPSS 0.3%CVE-2024-48289MEDIUMAn issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via sEPSS 0.3%CVE-2024-43700HIGHxfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow EPSS 0.3%CVE-2021-3569—A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could resulEPSS 0.3%CVE-2023-27968HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.3%CVE-2025-10889HIGHCATPART File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-48806MEDIUMBuffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a craftEPSS 0.3%CVE-2022-42261HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may leaEPSS 0.3%CVE-2024-35410MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackersEPSS 0.3%CVE-2025-25453MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.EPSS 0.3%CVE-2025-25458MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.EPSS 0.3%CVE-2024-30799MEDIUMAn issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach REPSS 0.3%CVE-2025-27834HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document tEPSS 0.3%CVE-2025-43312MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.EPSS 0.3%