Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-4397MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series EPSS 0.2%CVE-2022-4969MEDIUMbwoodsend rockhopper Binary Parser ragged_array.c count_rows buffer overflowEPSS 0.2%CVE-2024-3506HIGHCamera Driver possible Buffer OverflowEPSS 0.2%CVE-2024-48426MEDIUMA segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSEPSS 0.2%CVE-2024-54568MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may leaEPSS 0.2%CVE-2026-0154HIGHIn Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote coEPSS 0.2%CVE-2025-1430HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-0160HIGHIn TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds cEPSS 0.2%CVE-2025-46713HIGHSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_SET_SECURE_PARAM)EPSS 0.2%CVE-2024-31007MEDIUMBuffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected coEPSS 0.2%CVE-2026-0164HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additionalEPSS 0.2%CVE-2023-43569MEDIUMA buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegesEPSS 0.2%CVE-2023-43571MEDIUMA buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevatEPSS 0.2%CVE-2023-43581MEDIUMA buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2023-43573MEDIUMA buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackerEPSS 0.2%CVE-2023-43567MEDIUMA buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevEPSS 0.2%CVE-2023-43577MEDIUMA buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privilegeEPSS 0.2%CVE-2023-5075MEDIUMA buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevatedEPSS 0.2%CVE-2023-3494—bhyve privileged guest escape via fwctlEPSS 0.2%CVE-2023-43578MEDIUMA buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privilegEPSS 0.2%