Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-27834HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document tEPSS 0.3%CVE-2026-92043HIGHPrivilege escalation due to incorrect boundary conditions in the Audio/Video componentEPSS 0.3%CVE-2026-92014HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2024-32324HIGHBuffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code EPSS 0.3%CVE-2022-47090HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check EPSS 0.3%CVE-2022-42271HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2022-42274HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2024-58106MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58110MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58109MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58108MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-56557HIGHiio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xferEPSS 0.3%CVE-2024-31963MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.3%CVE-2024-35422HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2023-52364MEDIUMVulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may EPSS 0.3%CVE-2026-18280LOWSony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2024-12194HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2024-53335HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.EPSS 0.3%CVE-2026-1108MEDIUMcijliu librtsp rtsp_rely_dumps buffer overflowEPSS 0.2%CVE-2024-26797HIGHdrm/amd/display: Prevent potential buffer overflow in map_hw_resourcesEPSS 0.2%