Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-52062MEDIUMPotential stack buffer write overflow in Connext applications while parsing malicious XML types documentEPSS 0.2%CVE-2026-84632HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2018-25345HIGH10-Strike Network Scanner 3.0 Local Buffer Overflow SEHEPSS 0.2%CVE-2022-40540HIGHBuffer copy without checking the size of input in Linux KernelEPSS 0.2%CVE-2018-25314HIGHAllok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer OverflowEPSS 0.2%CVE-2025-61147MEDIUMstrukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(EPSS 0.2%CVE-2021-25461MEDIUMAn improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.EPSS 0.2%CVE-2025-25522HIGHBuffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting opEPSS 0.2%CVE-2022-35928HIGHAES Crypt for Linux Password Security VulnerabilityEPSS 0.2%CVE-2026-65398HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27EPSS 0.2%CVE-2025-8736MEDIUMGNU cflow Lexer c.c yylex buffer overflowEPSS 0.2%CVE-2018-25315HIGHAlloksoft Video joiner 4.6.1217 Buffer Overflow via License NameEPSS 0.2%CVE-2025-10887HIGHMODEL File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2018-25356HIGHSIPp 3.6 Local Buffer Overflow via Command-line ArgumentsEPSS 0.2%CVE-2025-5038HIGHX_T File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2018-25432HIGHArm Whois 3.11 Buffer Overflow via ASLR BypassEPSS 0.2%CVE-2025-28164MEDIUMBuffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() funcEPSS 0.2%CVE-2025-28162MEDIUMBuffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSaniEPSS 0.2%CVE-2018-25355HIGHAudiograbber 1.83 Local Buffer Overflow via SEHEPSS 0.2%CVE-2018-25299HIGHPrime95 29.4b8 Local Buffer Overflow via SEHEPSS 0.2%