Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2021-41216MEDIUMHeap buffer overflow in `Transpose`EPSS 0.2%CVE-2026-5164MEDIUMVirtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap requestEPSS 0.2%CVE-2025-25523MEDIUMBuffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related tEPSS 0.2%CVE-2023-33092HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.2%CVE-2020-8944MEDIUMUnchecked buffer overrun in ecall_restoreEPSS 0.2%CVE-2018-25301HIGHEasy MPEG to DVD Burner 1.7.11 SEH Local Buffer OverflowEPSS 0.2%CVE-2018-25302HIGHAllok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEHEPSS 0.2%CVE-2023-33017HIGHBuffer Copy Without Checking Size of Input in BootEPSS 0.2%CVE-2023-33087HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in CoreEPSS 0.2%CVE-2023-28580MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.2%CVE-2025-49495HIGHAn issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor commaEPSS 0.2%CVE-2023-33024MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Radio Interface LayerEPSS 0.2%CVE-2018-25264MEDIUMTransMac 12.2 Denial of Service via License Key FieldEPSS 0.2%CVE-2025-53966HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211 vendor command leadEPSS 0.2%CVE-2023-28579MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.2%CVE-2025-46776MEDIUMA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiEEPSS 0.2%CVE-2024-52065MEDIUMPotential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systemsEPSS 0.2%CVE-2024-52064MEDIUMPotential stack buffer write overflow in Connext applications while parsing malicious license fileEPSS 0.2%CVE-2021-46746MEDIUMLack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with accessEPSS 0.2%CVE-2018-25304HIGHFree Download Manager 2.0 Build 417 Local Buffer Overflow SEHEPSS 0.2%