Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-6604HIGHMemory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13EPSS 0.5%CVE-2026-4687CRITICALSandbox escape due to incorrect boundary conditions in the Telemetry componentEPSS 0.5%CVE-2023-52946HIGHBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client beforEPSS 0.5%CVE-2023-52307HIGHStack overflow in paddle.linalg.lu_unpackEPSS 0.5%CVE-2024-22749HIGHGPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_wrEPSS 0.5%CVE-2018-1100—zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploEPSS 0.5%CVE-2024-23077HIGHJFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disEPSS 0.5%CVE-2024-27908MEDIUMA buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.EPSS 0.5%CVE-2023-47091HIGHAn issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10EPSS 0.5%CVE-2026-24112HIGHAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. WhenEPSS 0.5%CVE-2024-38951MEDIUMA buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.EPSS 0.5%CVE-2025-14196HIGHH3C Magic B1 aspForm sub_44de0 buffer overflowEPSS 0.5%CVE-2020-14354—A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. TEPSS 0.5%CVE-2022-20927HIGHA vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software EPSS 0.5%CVE-2023-33082CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HostEPSS 0.5%CVE-2023-33083CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HostEPSS 0.5%CVE-2024-34244HIGHlibmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed EPSS 0.5%CVE-2024-46558HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows EPSS 0.5%CVE-2024-46561HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows atEPSS 0.5%CVE-2020-21427HIGHBuffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary coEPSS 0.5%