Falhas do tipo CWE-120

3.169 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2018-9386MEDIUMIn reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could EPSS 0.1%CVE-2018-9403HIGHIn the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missingEPSS 0.1%CVE-2023-21143—In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could leEPSS 0.1%CVE-2022-47335MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47362MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47464MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47463MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47336MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2025-47335MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2025-47334MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2024-40659MEDIUMIn getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation featEPSS 0.1%CVE-2024-47032HIGHIn construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead toEPSS 0.1%CVE-2025-26434MEDIUMIn libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additioEPSS 0.1%CVE-2025-47321HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2017-13308MEDIUMIn tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validaEPSS 0.1%CVE-2025-31712MEDIUMIn cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no EPSS 0.1%CVE-2025-47394HIGHBuffer Copy Without Checking Size of Input in DSP ServiceEPSS 0.1%CVE-2025-47388HIGHBuffer Copy without Checking Size of Input in DSP ServiceEPSS 0.1%CVE-2025-36931HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2026-21382HIGHBuffer Copy Without Checking Size of Input in Power Management ICEPSS 0.1%