Falhas do tipo CWE-120

3.168 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-36928HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalaEPSS 0.1%CVE-2025-36930HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2025-36927HIGHIn GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. This could lead to lEPSS 0.1%CVE-2025-21426MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2023-21135—In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validatiEPSS 0.1%CVE-2025-27043HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.1%CVE-2025-27052HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2025-27058HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2022-48439MEDIUMIn cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2024-53013MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2024-25984MEDIUMIn dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local inforEPSS 0.1%CVE-2022-47487MEDIUMIn thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local EPSS 0.1%CVE-2026-55290LOWIn setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local informatiEPSS 0.1%CVE-2025-21445HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2025-21444HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2024-27225MEDIUMIn sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informEPSS 0.1%CVE-2025-21476HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2025-47341HIGHBuffer Copy Without Checking Size of Input in CameraEPSS 0.1%CVE-2023-52346MEDIUMIn modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with SysEPSS 0.1%CVE-2025-27072MEDIUMBuffer Copy Without Checking Size of Input in Automotive Vehicle NetworksEPSS 0.1%