Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2020-8937MEDIUMArbitrary enclave memory location write from untrusted environmentEPSS 0.1%CVE-2018-25285MEDIUMFathom 2.4 Denial of Service via Authorization Code Buffer OverflowEPSS 0.1%CVE-2021-25469MEDIUMA possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.EPSS 0.1%CVE-2025-24519MEDIUMBuffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of priEPSS 0.1%CVE-2018-25296MEDIUMP10 Central Management Software 1.4.13 Denial of ServiceEPSS 0.1%CVE-2018-25287MEDIUMDrive Power Manager 1.10 Denial of Service via Name FieldEPSS 0.1%CVE-2018-25280MEDIUMInfiltrator Network Security Scanner 4.6 Denial of ServiceEPSS 0.1%CVE-2024-33052HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2024-33042HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2024-33054HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Computer VisionEPSS 0.1%CVE-2026-20436MEDIUMIn wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilEPSS 0.1%CVE-2026-20794CRITICALBuffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers mayEPSS 0.1%CVE-2025-54632MEDIUMVulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect sEPSS 0.1%CVE-2026-58549MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2022-25712MEDIUMMemory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOEPSS 0.1%CVE-2026-58550MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2026-49895LOWIn get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This couEPSS 0.1%CVE-2018-25273MEDIUMCrossFont 7.5 Denial of Service via License Key FieldEPSS 0.1%CVE-2024-43055HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2026-58553MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%