Falhas do tipo CWE-120

3.166 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-28759MEDIUMA crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.EPSS 0.2%CVE-2026-1109MEDIUMcijliu librtsp rtsp_parse_request buffer overflowEPSS 0.2%CVE-2024-26797HIGHdrm/amd/display: Prevent potential buffer overflow in map_hw_resourcesEPSS 0.2%CVE-2019-25349MEDIUMscadaApp for iOS 1.1.4.0 - 'Servername' Denial of ServiceEPSS 0.2%CVE-2025-55495MEDIUMTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.EPSS 0.2%CVE-2025-25529MEDIUMBuffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configEPSS 0.2%CVE-2020-37213MEDIUMTextCrawler Pro3.1.1 - Denial of ServiceEPSS 0.2%CVE-2025-25525MEDIUMBuffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the sEPSS 0.2%CVE-2025-25527MEDIUMBuffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the confiEPSS 0.2%CVE-2024-30165HIGHAmazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wEPSS 0.2%CVE-2025-25526MEDIUMBuffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration EPSS 0.2%CVE-2019-25353MEDIUMFoscam Video Management System 1.1.4.9 - 'Username' Denial of ServiceEPSS 0.2%CVE-2024-32228MEDIUMFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.EPSS 0.2%CVE-2023-51796LOWBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reversEPSS 0.2%CVE-2025-65226MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.EPSS 0.2%CVE-2024-8882MEDIUMA buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow anEPSS 0.2%CVE-2025-3139MEDIUMcode-projects Bus Reservation System Login Form login buffer overflowEPSS 0.2%CVE-2023-32356HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28211HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-29177MEDIUMMultiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and befoEPSS 0.2%