Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-35106MEDIUMNEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cauEPSS 0.5%CVE-2021-34780MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.5%CVE-2021-34779MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.5%CVE-2024-8748HIGHA buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through EPSS 0.5%CVE-2024-33783MEDIUMMP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SileEPSS 0.5%CVE-2025-3854HIGHH3C GR-3000AX HTTP POST Request aspForm Edit_List_SSID buffer overflowEPSS 0.5%CVE-2024-13503CRITICALStack-Based Buffer Overflow in Newtec's update signaling causes RCEEPSS 0.5%CVE-2024-25165HIGHA global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.EPSS 0.5%CVE-2023-43907HIGHOptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.EPSS 0.5%CVE-2026-41476HIGHDeskflow: clipboard deserialization global-buffer-overflowEPSS 0.5%CVE-2024-37606MEDIUMA Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTEPSS 0.5%CVE-2023-40031HIGHNotepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertEPSS 0.5%CVE-2025-50654HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp enEPSS 0.5%CVE-2025-50649HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shutEPSS 0.5%CVE-2025-50645HIGHA vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_listEPSS 0.5%CVE-2025-50653HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_groEPSS 0.5%CVE-2025-50646HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_tEPSS 0.5%CVE-2025-50648HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.EPSS 0.5%CVE-2025-50647HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoEPSS 0.5%CVE-2025-50644HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.EPSS 0.5%