Falhas do tipo CWE-120

3.168 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2022-25746HIGHBuffer Copy Without Checking Size of Input in KernelEPSS 0.1%CVE-2023-21640MEDIUMBuffer Copy Without Checking Size of Input in LinuxEPSS 0.1%CVE-2022-33230MEDIUMBuffer copy without checking the size of input in FM HostEPSS 0.1%CVE-2022-33224MEDIUMBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2023-21639MEDIUMBuffer Copy Without Checking the Size of Input in AudioEPSS 0.1%CVE-2023-21649MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLANEPSS 0.1%CVE-2023-21635MEDIUMBuffer Copy without Checking Size of Input in Data Network Stack & ConnectivityEPSS 0.1%CVE-2022-33226MEDIUMBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2023-32859MEDIUMIn meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with SyEPSS 0.1%CVE-2024-56450MEDIUMBuffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-24283LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of SEPSS 0.1%CVE-2018-25281MEDIUMiCash 7.6.5 Denial of Service via Connect to ServerEPSS 0.1%CVE-2025-47372CRITICALBuffer Copy Without Checking Size of Input in BootEPSS 0.1%CVE-2025-0045MEDIUMImproper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potEPSS 0.1%CVE-2021-25467MEDIUMAssuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release EPSS 0.1%CVE-2023-28547HIGHBuffer Copy Without Checking Size of Input in SPS ApplicationsEPSS 0.1%CVE-2023-33023HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in SPS-ApplicationsEPSS 0.1%CVE-2023-43540HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.1%CVE-2026-18321MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsecEPSS 0.1%CVE-2023-33072CRITICALBuffer copy without checking size of Input in CoreEPSS 0.1%