Falhas do tipo CWE-120

3.168 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-33031HIGHBuffer Copy Without Checking Size of Input in Automotive AudioEPSS 0.1%CVE-2023-28546HIGHBuffer Copy Without Checking Size of Input in SPS ApplicationsEPSS 0.1%CVE-2024-23378MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-28539MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.1%CVE-2023-43515MEDIUMBuffer copy without checking size of input (Classic buffer overflow) in HLOSEPSS 0.1%CVE-2021-43614MEDIUMVariableEditSmm: Error checking of UEFI variables could cause buffer overflow, leading to code executionEPSS 0.1%CVE-2023-33035HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2026-34866MEDIUMOut-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confiEPSS 0.1%CVE-2023-43526MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33068MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-43525MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-22384MEDIUMBuffer Copy Without Checking Size of Input in VR ServiceEPSS 0.1%CVE-2024-49829MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in CameraEPSS 0.1%CVE-2024-45541HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN Windows HostEPSS 0.1%CVE-2023-43524MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33069MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-33077MEDIUMBuffer Copy Without Checking Size of Input in HLOSEPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2024-56453MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2024-56456MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%