Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2022-39067MEDIUMThere is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticateEPSS 0.7%CVE-2023-43314HIGH** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow EPSS 0.7%CVE-2026-24113CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When thEPSS 0.6%CVE-2023-1161MEDIUMISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or craEPSS 0.6%CVE-2026-24111CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. WhenEPSS 0.6%CVE-2026-24108CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When thEPSS 0.6%CVE-2026-24109CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. WhenEPSS 0.6%CVE-2024-36650HIGHTOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/EPSS 0.6%CVE-2026-2139HIGHTenda TX9 fast_setting_wifi_set sub_432580 buffer overflowEPSS 0.6%CVE-2023-47430MEDIUMStack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer(EPSS 0.6%CVE-2025-6091HIGHH3C GR-3000AX aspForm UpdateIpv6Params buffer overflowEPSS 0.6%CVE-2025-6090HIGHH3C GR-5400AX aspForm UpdateIpv6params buffer overflowEPSS 0.6%CVE-2024-52757LOWD-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.EPSS 0.6%CVE-2026-2086HIGHUTT HiPER 810G Management formFireWall strcpy buffer overflowEPSS 0.6%CVE-2024-37861CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl procEPSS 0.6%CVE-2023-22652LOWStack buffer overflow in "read_file" functionEPSS 0.6%CVE-2015-10123HIGHWago: Buffer Copy without Checking Size of Input in wbm of multiple productsEPSS 0.6%CVE-2023-45044LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45042LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45043LOWQTS, QuTS heroEPSS 0.6%