Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2022-49040MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology DrivEPSS 0.2%CVE-2022-49041MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology DriEPSS 0.2%CVE-2025-0303HIGHLiteos_a has a buffer overflow vulnerabilityEPSS 0.2%CVE-2019-25326MEDIUMipPulse 1.92 - 'Enter Key' Denial of ServiceEPSS 0.2%CVE-2026-42450HIGHOpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parserEPSS 0.2%CVE-2026-64705MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS EPSS 0.2%CVE-2026-30006MEDIUMXnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.EPSS 0.2%CVE-2026-65357HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOEPSS 0.2%CVE-2026-84489MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, EPSS 0.2%CVE-2026-57246HIGHFoxit PDF Editor/Reader Signature Buffer Overflow VulnerabilityEPSS 0.2%CVE-2018-25369MEDIUMVisual Ping 0.8.0.0 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2025-1253MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-28841MEDIUMA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memoEPSS 0.2%CVE-2026-0157MEDIUMIn RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosurEPSS 0.2%CVE-2026-84577HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app maEPSS 0.2%CVE-2026-30981MEDIUMiccDEV has a heap-buffer-overflow read in CIccXmlArrayType<>EPSS 0.2%CVE-2018-25367MEDIUMNASA openVSP 3.16.1 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2026-43681HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-55277HIGHIn checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could leadEPSS 0.2%CVE-2024-52059MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.EPSS 0.2%