Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2021-29520LOWHeap buffer overflow in `Conv3DBackprop*`EPSS 0.2%CVE-2023-38581HIGHBuffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation EPSS 0.2%CVE-2023-27957HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously craEPSS 0.2%CVE-2026-20449MEDIUMIn Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connectedEPSS 0.2%CVE-2025-44951HIGHA missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a locEPSS 0.2%CVE-2024-6564MEDIUMBuffer overflow in Rensas RCAREPSS 0.2%CVE-2023-29932MEDIUMllvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.EPSS 0.2%CVE-2023-37926MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through EPSS 0.2%CVE-2025-27833HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.EPSS 0.2%CVE-2023-28736MEDIUMBuffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2021-41221HIGHAccess to invalid memory during shape inference in `Cudnn*` opsEPSS 0.2%CVE-2025-57572MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.EPSS 0.2%CVE-2025-57573MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.EPSS 0.2%CVE-2022-50687MEDIUMCobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password FieldEPSS 0.2%CVE-2025-1660HIGHDWFX File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2022-44455MEDIUMThe appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.EPSS 0.2%CVE-2026-76699MEDIUMUnauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.2%CVE-2022-27242—A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial EPSS 0.2%CVE-2021-22547MEDIUMBuffer overrun in Google Cloud IoT Device SDK for Embedded CEPSS 0.2%CVE-2024-50090HIGHdrm/xe/oa: Fix overflow in oa batch bufferEPSS 0.2%