Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-28741HIGHBuffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2024-9997HIGHAutodesk AutoCAD DWG File Parsing Memory Corruption Code Execution VulnerabilityEPSS 0.2%CVE-2026-90801MEDIUMGNU Binutils ld cache.c cache_bwrite buffer overflowEPSS 0.2%CVE-2026-71612HIGHBuffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_EPSS 0.2%CVE-2025-9557HIGHBluetooth: Mesh: Out-of-Bound Write in gen_prov_contEPSS 0.2%CVE-2024-8592HIGHAutodesk AutoCAD CATPART File Parsing Memory Corruption Code Execution VulnerabilityEPSS 0.2%CVE-2022-26414MEDIUMA potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, wEPSS 0.2%CVE-2026-84581HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe EPSS 0.2%CVE-2025-50361MEDIUMBuffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593feEPSS 0.2%CVE-2024-6199HIGHUnauthenticated Remote Code ExecutionEPSS 0.2%CVE-2024-23079MEDIUMJGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compaEPSS 0.2%CVE-2023-22661HIGHBuffer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilegeEPSS 0.2%CVE-2026-24344HIGHMultiple Buffer Overflows in EZCast Pro II DongleEPSS 0.2%CVE-2024-44157MEDIUMA stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13EPSS 0.2%CVE-2025-12440MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2025-57571MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.EPSS 0.2%CVE-2025-57570MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.EPSS 0.2%CVE-2025-57569MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.EPSS 0.2%CVE-2026-6694MEDIUMGimp: gimp file-png plugin: denial of service via oversized apng trns chunkEPSS 0.2%CVE-2026-71613HIGHBuffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_pEPSS 0.2%