Falhas do tipo CWE-120

3.167 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2026-58552MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2026-58551MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2025-36924HIGHIn ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This EPSS 0.1%CVE-2022-33277HIGHBuffer copy without checking size of input in modemEPSS 0.1%CVE-2022-33278HIGHBuffer copy without checking the size of input in HLOSEPSS 0.1%CVE-2022-25655HIGHBuffer copy without checking the size of input in WLAN HAL.EPSS 0.1%CVE-2022-25724HIGHMemory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2023-33030CRITICALBuffer Copy without Checking Size of Input in HLOSEPSS 0.1%CVE-2024-23375MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in RILEPSS 0.1%CVE-2023-24284LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.EPSS 0.1%CVE-2022-39121MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-39122MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2023-24291LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.EPSS 0.1%CVE-2023-24287LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.EPSS 0.1%CVE-2023-24285LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long movEPSS 0.1%CVE-2022-39120MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2022-33217HIGHMemory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernEPSS 0.1%CVE-2025-20149MEDIUMA vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affectedEPSS 0.1%CVE-2022-42760MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-8412LOWVMDP: Potential buffer overflow in the RtlQueryRegistryValues functionEPSS 0.1%