Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2023-32972LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-41277MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-41276MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-32971LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2026-57874HIGHGV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)EPSS 0.5%CVE-2023-37929MEDIUMThe buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remotEPSS 0.5%CVE-2018-4301CRITICALThis issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.EPSS 0.5%CVE-2025-7673CRITICALA buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 EPSS 0.5%CVE-2024-31951MEDIUMIn the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_EPSS 0.5%CVE-2026-28953HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2023-52309HIGHHeap buffer overflow in paddle.repeat_interleaveEPSS 0.5%CVE-2026-43658HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.5%CVE-2023-46960HIGHBuffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp modEPSS 0.5%CVE-2026-28904HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-76705MEDIUMAuthenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-28905HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2025-29137CRITICALTenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cEPSS 0.5%CVE-2025-4446HIGHH3C GR-5400AX aspForm Edit_List_SSID buffer overflowEPSS 0.5%CVE-2024-57578MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.EPSS 0.5%CVE-2025-4440HIGHH3C GR-1800AX aspForm EnableIpv6 buffer overflowEPSS 0.5%