Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-68114MEDIUMCapstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflowEPSS 0.2%CVE-2022-1110MEDIUMA buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of serEPSS 0.2%CVE-2026-71613HIGHBuffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_pEPSS 0.2%CVE-2022-0636MEDIUMA denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.EPSS 0.2%CVE-2025-6634HIGHTGA File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-30985HIGHiccDEV has a heap-based buffer overflow write in CIccMatrixMath::SetRange()EPSS 0.2%CVE-2026-30983HIGHiccDEV has a stack buffer overflow in icFixXml()EPSS 0.2%CVE-2026-31795HIGHiccDEV has a stack buffer overflow write in CIccXform3DLut::Apply()EPSS 0.2%CVE-2023-52080HIGHIEIT NF5280M6 UEFI firmware through 8.4 has a pool overflow vulnerability, caused by improper use of the gRT->GetVariable() function. AttackEPSS 0.2%CVE-2026-30987HIGHiccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()EPSS 0.2%CVE-2026-90804LOWGNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflowEPSS 0.2%CVE-2022-48696HIGHregmap: spi: Reserve space for register address/paddingEPSS 0.2%CVE-2023-47217MEDIUMArkruntime has a buffer overflow vulnerabilityEPSS 0.2%CVE-2024-54105MEDIUMRead/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2026-28981HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2023-4029MEDIUMA buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with locEPSS 0.2%CVE-2023-4028MEDIUMA buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker wEPSS 0.2%CVE-2026-64747HIGHA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%CVE-2023-34419MEDIUMA buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local accEPSS 0.2%CVE-2026-43776HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%