Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2026-0849LOWcrypto: ATAES132A response length allows stack buffer overflowEPSS 0.2%CVE-2020-37215MEDIUMMSN Password Recovery 1.30 - Denial of ServiceEPSS 0.2%CVE-2025-29481MEDIUMBuffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of lEPSS 0.2%CVE-2023-23535MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11EPSS 0.2%CVE-2020-8905LOWConfidential Information Disclosure vulnerability in AsyloEPSS 0.2%CVE-2023-27955MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvEPSS 0.2%CVE-2026-20608MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iEPSS 0.2%CVE-2025-29482MEDIUMBuffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) proceEPSS 0.2%CVE-2023-20168HIGHA vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to causeEPSS 0.2%CVE-2022-3077—A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_EPSS 0.2%CVE-2021-33897MEDIUMA buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to cause a denial of servicEPSS 0.2%CVE-2020-37164MEDIUMAbsoluteTelnet 11.12 - "license entry" Denial of ServiceEPSS 0.2%CVE-2020-37165MEDIUMAbsoluteTelnet 11.12 - "license name" Denial of ServiceEPSS 0.2%CVE-2023-30083MEDIUMBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in utiEPSS 0.2%CVE-2023-24809MEDIUMNetHack Call command buffer overflowEPSS 0.2%CVE-2022-21742MEDIUMRealtek USB FE/1GbE/2.5GbE/5GbE NIC Family - Buffer OverflowEPSS 0.2%CVE-2023-30085MEDIUMBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the cws2fws functioEPSS 0.2%CVE-2024-55045HIGHFirmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_EPSS 0.2%CVE-2025-46714HIGHSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_GET_SECURE_PARAM)EPSS 0.2%CVE-2023-32401HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS VenEPSS 0.2%