Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-23236HIGHBuffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operationEPSS 0.2%CVE-2026-7454HIGHWRL File Parsing Memory Corruption in Autodesk 3ds MaxEPSS 0.2%CVE-2025-48611CRITICALIn DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation oEPSS 0.2%CVE-2024-0146HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successfuEPSS 0.2%CVE-2026-7452HIGHWRL File Parsing Memory Corruption in Autodesk 3ds MaxEPSS 0.2%CVE-2026-30979HIGHiccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp()EPSS 0.2%CVE-2026-52489HIGHBuffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameTEPSS 0.2%CVE-2022-3742MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2020-36994MEDIUMQlikView 12.50.20000.0 - 'FTP Server Address' Denial of ServiceEPSS 0.2%CVE-2025-9558HIGHBluetooth: Mesh: Out-of-Bound Write in gen_prov_startEPSS 0.2%CVE-2026-36189MEDIUMBuffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106EPSS 0.2%CVE-2024-57510HIGHBuffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary codeEPSS 0.2%CVE-2022-41802MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.EPSS 0.2%CVE-2024-57509HIGHBuffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary codeEPSS 0.2%CVE-2021-26409HIGHInsufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SEPSS 0.2%CVE-2026-84497HIGHA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS EPSS 0.2%CVE-2024-37816MEDIUMQuectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.EPSS 0.2%CVE-2022-23817HIGHInsufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application toEPSS 0.2%CVE-2026-6691HIGHMongoDB C Driver Cyrus SASL Canonicalization Buffer OverflowEPSS 0.2%CVE-2026-20302MEDIUMCisco RoomOS Stack Overflow VulnerabilityEPSS 0.2%