Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2019-14835HIGHA buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue EPSS 0.6%CVE-2024-42011HIGHThe Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.EPSS 0.6%CVE-2026-63453HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.6%CVE-2022-43392MEDIUMA buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an autheEPSS 0.6%CVE-2026-20652HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.6%CVE-2023-23494MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged netwoEPSS 0.6%CVE-2025-25565CRITICALSoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the SuEPSS 0.6%CVE-2025-15460HIGHUTT 进取 520W formPptpClientConfig strcpy buffer overflowEPSS 0.6%CVE-2024-37863CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl procEPSS 0.6%CVE-2024-52754LOWD-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.EPSS 0.6%CVE-2024-45971CRITICALMultiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a maliEPSS 0.6%CVE-2024-45970CRITICALMultiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a maliEPSS 0.6%CVE-2026-7735MEDIUMosrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflowEPSS 0.6%CVE-2024-40084CRITICALA Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitraryEPSS 0.6%CVE-2024-40085CRITICALA Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticaEPSS 0.6%CVE-2024-40086CRITICALA Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unEPSS 0.6%CVE-2025-49464MEDIUMZoom Clients for Windows- Classic Buffer OverflowEPSS 0.6%CVE-2026-70415HIGHDell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remotEPSS 0.6%CVE-2020-37068HIGHKonica Minolta FTP Utility 1.0 - 'LIST' Denial of ServiceEPSS 0.6%CVE-2025-14140HIGHUTT 进取 520W websHostFilter strcpy buffer overflowEPSS 0.6%