Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2022-23428HIGHAn improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.EPSS 0.2%CVE-2026-29976MEDIUMBuffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive information via the gEPSS 0.1%CVE-2018-25307HIGHSysGauge Pro 4.6.12 Local Buffer Overflow SEHEPSS 0.1%CVE-2018-25328HIGHVX Search 10.6.18 Local Buffer Overflow via Directory FieldEPSS 0.1%CVE-2019-25733HIGHNetShareWatcher 1.5.8.0 SEH Buffer OverflowEPSS 0.1%CVE-2019-25735HIGHAllPlayer 7.4 Local Buffer Overflow via SEH UnicodeEPSS 0.1%CVE-2026-11885HIGHPower System update in Buffer CopyEPSS 0.1%CVE-2020-37234MEDIUMInternet Download Manager 6.38.12 Scheduler Buffer OverflowEPSS 0.1%CVE-2024-21464HIGHBuffer Copy Without Checking Size of Input in Data Network Stack & ConnectivityEPSS 0.1%CVE-2018-25263HIGHFaleemi Desktop Software 1.8.2 Local Buffer Overflow SEHEPSS 0.1%CVE-2023-6334MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow BuEPSS 0.1%CVE-2018-25283HIGHiSmartViewPro 1.5 Buffer Overflow via SavePath ParameterEPSS 0.1%CVE-2019-25736HIGHLabF nfsAxe 3.7 Ping Client Buffer OverflowEPSS 0.1%CVE-2018-25278MEDIUMPicaJet FX 2.6.5 Denial of Service via Registration FieldsEPSS 0.1%CVE-2024-0816MEDIUMThe buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denEPSS 0.1%CVE-2025-22897LOWArkcompiler Ets Runtime has a buffer overflow vulnerabilityEPSS 0.1%CVE-2026-53203HIGHaccel/ivpu: Add buffer overflow check in MS get_info_ioctlEPSS 0.1%CVE-2025-23234LOWArkcompiler Ets Runtime has a buffer overflow vulnerabilityEPSS 0.1%CVE-2025-25052LOWarkcompiler_ets_runtime has a buffer overflow vulnerabilityEPSS 0.1%CVE-2023-33055HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%