Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2026-36801HIGHShenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindRule parameter of the forEPSS 0.6%CVE-2026-36800HIGHShenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindIndex parameter of the foEPSS 0.6%CVE-2026-36818HIGHShenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter ofEPSS 0.6%CVE-2025-25668CRITICALTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.EPSS 0.6%CVE-2026-36815HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSEPSS 0.6%CVE-2026-36808HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of thEPSS 0.6%CVE-2026-36809HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of theEPSS 0.6%CVE-2026-36811HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDeEPSS 0.6%CVE-2024-46424HIGHTOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to EPSS 0.6%CVE-2024-34905HIGHFlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackersEPSS 0.6%CVE-2024-31504HIGHBuffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service EPSS 0.6%CVE-2025-3496HIGHAUMA Riester: Buffer overflow in service telegramEPSS 0.6%CVE-2024-37607MEDIUMA Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a craftEPSS 0.5%CVE-2026-38426HIGHBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scEPSS 0.5%CVE-2024-57480CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. AttackersEPSS 0.5%CVE-2024-48984CRITICALAn issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list ofEPSS 0.5%CVE-2024-57479CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. AttackeEPSS 0.5%CVE-2023-41276MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-32971LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-41275MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%