Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-52304HIGHStack overflow in paddle.searchsortedEPSS 0.6%CVE-2023-26318MEDIUMXiaomi router web interface post-authorization stack overflowEPSS 0.6%CVE-2023-41280MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-41292LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-45036LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-45035LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-41279MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2024-47864MEDIUMhome 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote EPSS 0.6%CVE-2023-45037LOWQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2024-46045MEDIUMTenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.EPSS 0.6%CVE-2024-4143CRITICALCertain HP PC products using AMI BIOS – Buffer OverflowEPSS 0.6%CVE-2024-31040LOWBuffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial ofEPSS 0.6%CVE-2024-32763MEDIUMQTS, QuTS heroEPSS 0.6%CVE-2025-46785MEDIUMZoom Workplace Apps for Windows - Buffer Over-readEPSS 0.6%CVE-2026-20243HIGHClamAV ALZ Archive Processing Denial of Service VulnerabilityEPSS 0.6%CVE-2026-20217HIGHClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20244HIGHClamAV DMG File Processing Denial of Service VulnerabilityEPSS 0.6%CVE-2026-20213HIGHClamAV PE File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20214HIGHClamAV FSG File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%CVE-2026-20215HIGHClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption VulnerabilityEPSS 0.6%