Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-8892HIGHPRT File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-64722MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPaEPSS 0.2%CVE-2018-25290MEDIUMEasyboot 6.6.0 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-0165MEDIUMIn several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to reEPSS 0.2%CVE-2025-71263HIGHIn UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size oEPSS 0.2%CVE-2025-5048HIGHDGN File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2021-43072MEDIUMA buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 anEPSS 0.2%CVE-2026-0155MEDIUMIn ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information discEPSS 0.2%CVE-2021-26354MEDIUMInsufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory valEPSS 0.2%CVE-2026-0129MEDIUMIn RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure withEPSS 0.2%CVE-2022-24350MEDIUMAn issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lieEPSS 0.2%CVE-2025-24004MEDIUMUSB-C Buffer Overflow via Display Interface in EV Charging StationsEPSS 0.2%CVE-2025-25524MEDIUMBuffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to EPSS 0.2%CVE-2022-46824MEDIUMIn JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.EPSS 0.2%CVE-2022-37020MEDIUMHP PC BIOS May 2024 Security Updates for Potential Stack Buffer OverflowsEPSS 0.2%CVE-2018-25306MEDIUMPDFunite 0.41.0 Buffer Overflow via Malformed PDFEPSS 0.2%CVE-2026-48696MEDIUMFastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.EPSS 0.2%CVE-2026-52295LOWFFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavfEPSS 0.2%CVE-2025-69209MEDIUMArduinoCore-avr has Stack-Based Buffer Overflow in WString Float/Double ConstructorsEPSS 0.2%CVE-2024-0213HIGH A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause EPSS 0.2%