Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-43573MEDIUMA buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackerEPSS 0.2%CVE-2023-43581MEDIUMA buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2023-5075MEDIUMA buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevatedEPSS 0.2%CVE-2023-43569MEDIUMA buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegesEPSS 0.2%CVE-2023-3494—bhyve privileged guest escape via fwctlEPSS 0.2%CVE-2024-35419MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackeEPSS 0.2%CVE-2025-44952HIGHA missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a EPSS 0.2%CVE-2024-33876MEDIUMHDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.EPSS 0.2%CVE-2022-40137MEDIUMA buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arEPSS 0.2%CVE-2024-35420MEDIUMwac commit 385e1 was discovered to contain a heap overflow.EPSS 0.2%CVE-2024-35418MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackerEPSS 0.2%CVE-2020-37166MEDIUMAbsoluteTelnet 11.12 - 'SSH2/username' Denial of ServiceEPSS 0.2%CVE-2024-33875MEDIUMHDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruEPSS 0.2%CVE-2022-29210MEDIUMHeap buffer overflow due to incorrect hash function in TensorFlowEPSS 0.2%CVE-2020-37036HIGHRM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer OverflowEPSS 0.2%CVE-2024-48424MEDIUMA heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specificalEPSS 0.2%CVE-2020-37049HIGHFrigate 3.36.0.9 - 'Command Line' Local Buffer OverflowEPSS 0.2%CVE-2024-26785MEDIUMiommufd: Fix protection fault in iommufd_test_syz_conv_iovaEPSS 0.2%CVE-2021-47172MEDIUMiio: adc: ad7124: Fix potential overflow due to non sequential channel numbersEPSS 0.2%CVE-2025-44951HIGHA missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a locEPSS 0.2%