Falhas do tipo CWE-120

3.168 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-49830MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2024-56453MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2026-24076MEDIUMBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.1%CVE-2025-21443HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Automotive Vehicle NetworksEPSS 0.1%CVE-2023-21136—In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could leaEPSS 0.1%CVE-2024-48519MEDIUMBuffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denialEPSS 0.1%CVE-2026-16726MEDIUMBuffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.EPSS 0.1%CVE-2023-43538CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in TZ Secure OSEPSS 0.1%CVE-2023-43556CRITICALBuffer Copy Without Checking Size of Input in HypervisorEPSS 0.1%CVE-2024-38409HIGHBuffer Copy Without Checking Size of Input in WLAN Windows HostEPSS 0.1%CVE-2024-23368HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Qualcomm IPCEPSS 0.1%CVE-2023-24286LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.EPSS 0.1%CVE-2026-24080HIGHBuffer Copy Without Checking Size of Input in BiometricsEPSS 0.1%CVE-2018-9387HIGHIn multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local eEPSS 0.1%CVE-2024-38423HIGHBuffer Copy Without Checking Size of Input in Graphics LinuxEPSS 0.1%CVE-2023-43542HIGHBuffer Copy Without Checking Size of Input in Trusted Execution EnvironmentEPSS 0.1%CVE-2024-33030MEDIUMBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in PerformanceEPSS 0.1%CVE-2026-56978HIGHIn get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2026-55301HIGHIn Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation oEPSS 0.1%