Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-45043LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45042LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45039LOWQTS, QuTS heroEPSS 0.6%CVE-2024-41209HIGHA heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code ExecuEPSS 0.6%CVE-2019-25741CRITICALMobatek MobaXterm 12.1 Buffer Overflow via Sessions FileEPSS 0.6%CVE-2023-0977MEDIUM A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page EPSS 0.6%CVE-2024-25394MEDIUMA buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' charaEPSS 0.6%CVE-2025-20222HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Buffer VulnerabilityEPSS 0.6%CVE-2024-40130CRITICALopen5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.EPSS 0.6%CVE-2023-22399HIGHJunos OS: QFX10K Series: PFE crash upon receipt of specific genuine packets when sFlow is enabledEPSS 0.6%CVE-2026-34956MEDIUMOpenvswitch: open vswitch: denial of service via malformed ftp epasv commandEPSS 0.6%CVE-2025-22904CRITICALRE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.EPSS 0.6%CVE-2025-22916CRITICALRE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.EPSS 0.6%CVE-2025-22907CRITICALRE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.EPSS 0.6%CVE-2024-34252HIGHwasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupiEPSS 0.6%CVE-2025-25456CRITICALTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.EPSS 0.6%CVE-2025-46035HIGHBuffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTEPSS 0.6%CVE-2023-46256MEDIUMPX4-Autopilot Heap Buffer Overflow BugEPSS 0.6%CVE-2026-52189HIGHBuffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the goheaEPSS 0.6%CVE-2026-20911CRITICALA heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A speEPSS 0.6%