Falhas do tipo CWE-120

3.168 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-20149MEDIUMA vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affectedEPSS 0.1%CVE-2025-32732MEDIUMBuffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service.EPSS 0.1%CVE-2023-33113HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in KernelEPSS 0.1%CVE-2018-25297MEDIUMWansview 1.0.2 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2018-25305MEDIUMlibrsvg2-bin 2.40.13 Buffer Overflow via Malformed SVGEPSS 0.1%CVE-2022-33288CRITICALBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2023-33085HIGHBuffer Copy Without Checking Size of Input (Classic Buffer Overflow) in WearablesEPSS 0.1%CVE-2023-52551MEDIUMVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.1%CVE-2022-39118MEDIUMIn sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service inEPSS 0.1%CVE-2022-23431MEDIUMAn improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2018-25276MEDIUMRoboImport 1.2.0.72 Denial of Service via Registration FieldsEPSS 0.1%CVE-2023-28559HIGHBuffer Copy Without Checking Size of Input in WLAN HALEPSS 0.1%CVE-2023-22386HIGHBuffer Copy Without Checking Size of Input in WLAN HOSTEPSS 0.1%CVE-2023-28544HIGHBuffer Copy without Checking the Size of Input in WLAN FirmwareEPSS 0.1%CVE-2023-24851HIGHBuffer Copy Without Checking Size of Input in WLAN HOSTEPSS 0.1%CVE-2023-21662HIGHBuffer Copy without Checking the Size of Input(Classic Buffer Overflow) in Core PlatformEPSS 0.1%CVE-2022-33232CRITICALBuffer copy without checking size of input in HypervisorEPSS 0.1%CVE-2022-33276HIGHBuffer copy without checking size of input in ModemEPSS 0.1%CVE-2023-21664HIGHBuffer Copy without Checking the Size of Input(Classic Buffer Overflow) in Core PlatformEPSS 0.1%CVE-2023-28560HIGHBuffer Copy Without Checking Size of Input in WLAN HALEPSS 0.1%