Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-50648HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.EPSS 0.5%CVE-2025-50654HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp enEPSS 0.5%CVE-2023-22745MEDIUMBuffer Overlow in TSS2_RC_Decode in tpm2-tssEPSS 0.5%CVE-2023-47625LOWGlobal Buffer Overflow leading to denial of service in PX4-AutopilotEPSS 0.5%CVE-2025-25280MEDIUMBuffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by CenEPSS 0.5%CVE-2024-12373CRITICALRockwell Automation PowerMonitor™ 1000 Denial of ServiceEPSS 0.5%CVE-2018-25426HIGHWinMTR 0.91 Denial of Service via Buffer OverflowEPSS 0.5%CVE-2025-29360HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCEPSS 0.5%CVE-2025-29363HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /gofoEPSS 0.5%CVE-2024-53695MEDIUMHBS 3 Hybrid Backup SyncEPSS 0.5%CVE-2024-31950MEDIUMIn FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt tEPSS 0.5%CVE-2025-29359HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfoEPSS 0.5%CVE-2023-25642MEDIUMTwo Vulnerabilities in Some ZTE Mobile Internet ProductsEPSS 0.5%CVE-2025-29362HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulEPSS 0.5%CVE-2024-55564CRITICALThe POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.EPSS 0.5%CVE-2025-55602CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.EPSS 0.5%CVE-2024-41435HIGHYugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.EPSS 0.5%CVE-2024-9197MEDIUMA post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions thrEPSS 0.5%CVE-2026-28847HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28875HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be ablEPSS 0.5%