CWE-120 · 3.626 kayıt
Sınır kontrolsüz arabellek kopyalama
Neden olur?
Veri kopyalanırken kaynağın uzunluğu, hedef arabelleğin boyutuyla karşılaştırılmıyor. Fazla veri, bitişik belleğin üzerine yazılır.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
char buf[256];memcpy(buf, pkt->data, pkt->len);Düzeltilmiş
char buf[256];if (pkt->len > sizeof(buf)) { return -EINVAL;}memcpy(buf, pkt->data, pkt->len);Nasıl önlenir?
- 01Kopyalamadan önce uzunluğu hedef boyutla karşılaştırın.
- 02Uzunluk alanını ağdan gelen veriden değil, doğrulanmış sınırlardan alın.
- 03Derleyici korumalarını ve bellek güvenli dilleri tercih edin.
Bu sınıftaki CVE’ler
3.626 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2017-7269Silahlaştırılmış | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Smicrosoft · internet information services · CWE-120 | Kritik9,8 | KEV | %99,8 | 26 Mar 2017 |
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
94Hemen | CVE-2016-10174Silahlaştırılmış | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.netgear · d6100 firmware · CWE-120 | Kritik9,8 | KEV | %83,3 | 30 Oca 2017 |
94Hemen | CVE-2018-6789Silahlaştırılmış | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Kritik9,8 | KEV | %82,1 | 8 Şub 2018 |
91Hemen | CVE-2016-6366Silahlaştırılmış | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,cisco · pix firewall software · CWE-120 | Yüksek8,8 | KEV | %87,6 | 18 Ağu 2016 |
90Hemen | CVE-2025-20333Silahlaştırılmış | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Dcisco · adaptive security appliance software · CWE-120 | Kritik9,9 | KEV | %70,7 | 25 Eyl 2025 |
87Hemen | CVE-2007-5659Silahlaştırılmış | Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file withadobe · acrobat · CWE-120 | Yüksek7,8 | KEV | %87,4 | 12 Şub 2008 |
86Hemen | CVE-2022-37055Silahlaştırılmış | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,dlink · go-rt-ac750 firmware · CWE-120 | Kritik9,8 | KEV | %55,5 | 28 Ağu 2022 |
85Hemen | CVE-2013-1331Silahlaştırılmış | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data microsoft · office · CWE-120 | Yüksek7,8 | KEV | %79,8 | 11 Haz 2013 |
83Hemen | CVE-2017-6862Silahlaştırılmış | NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypnetgear · wnr2000 firmware · CWE-120 | Kritik9,8 | KEV | %45,7 | 26 May 2017 |
79Bu hafta | CVE-2010-2572Silahlaştırılmış | Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 microsoft · powerpoint · CWE-120 | Yüksek7,8 | KEV | %58,6 | 9 Kas 2010 |
79Bu hafta | CVE-2006-2492Silahlaştırılmış | Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allowmicrosoft · office · CWE-120 | Yüksek8,8 | KEV | %48,1 | 19 May 2006 |
78Bu hafta | CVE-2023-33010Silahlaştırılmış | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX serizyxel · atp100 firmware · CWE-120 | Kritik9,8 | KEV | %28,8 | 24 May 2023 |
77Bu hafta | CVE-2023-41064Silahlaştırılmış | A buffer overflow issue was addressed with improved memory handling.apple · ipados · CWE-120 | Yüksek7,8 | KEV | %53,4 | 7 Eyl 2023 |
77Bu hafta | CVE-2023-33009Silahlaştırılmış | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX seriezyxel · atp100 firmware · CWE-120 | Kritik9,8 | KEV | %28,1 | 24 May 2023 |
77Bu hafta | CVE-2020-5135Silahlaştırılmış | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code sonicwall · sonicos · CWE-120 | Kritik9,8 | KEV | %26,9 | 12 Eki 2020 |
72Bu hafta | CVE-2016-0099Silahlaştırılmış | The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2microsoft · windows 10 1507 · CWE-120 | Yüksek7,8 | KEV | %37,0 | 9 Mar 2016 |
72Bu hafta | CVE-2020-15069Silahlaştırılmış | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlessophos · xg firewall firmware · CWE-120 | Kritik9,8 | KEV | %10,7 | 29 Haz 2020 |
71Bu hafta | CVE-2013-0641Silahlaştırılmış | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to executeadobe · acrobat · CWE-120 | Yüksek7,8 | KEV | %32,3 | 13 Şub 2013 |
68Bu hafta | CVE-2011-4862Silahlaştırılmış | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Kritik10,0 | — | %95,0 | 24 Ara 2011 |
66Bu hafta | CVE-2020-11984Kavram kanıtı | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCEapache · http server · CWE-120 | Kritik9,8 | — | %90,0 | 7 Ağu 2020 |
65Bu hafta | CVE-2021-3711İstismar yok | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Kritik9,8 | — | %87,8 | 24 Ağu 2021 |
63Bu hafta | CVE-2009-3023Silahlaştırılmış | Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to exemicrosoft · internet information server · CWE-120 | Kritik9,0 | — | %90,9 | 31 Ağu 2009 |
63Bu hafta | CVE-2004-0210Silahlaştırılmış | The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly bmicrosoft · interix · CWE-120 | Yüksek7,8 | KEV | %7,2 | 6 Ağu 2004 |
62Bu hafta | CVE-2020-8012Silahlaştırılmış | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (cbroadcom · unified infrastructure management · CWE-120 | Kritik9,8 | — | %77,4 | 18 Şub 2020 |
- CVE-2017-726999Hemen
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100microsoft · internet information services26 Mar 2017
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2016-1017494Hemen
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83netgear · d6100 firmware30 Oca 2017
- CVE-2018-678994Hemen
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %82exim · exim8 Şub 2018
- CVE-2016-636691Hemen
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %88cisco · pix firewall software18 Ağu 2016
- CVE-2025-2033390Hemen
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %71cisco · adaptive security appliance software25 Eyl 2025
- CVE-2007-565987Hemen
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %87adobe · acrobat12 Şub 2008
- CVE-2022-3705586Hemen
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %56dlink · go-rt-ac750 firmware28 Ağu 2022
- CVE-2013-133185Hemen
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %80microsoft · office11 Haz 2013
- CVE-2017-686283Hemen
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication byp
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %46netgear · wnr2000 firmware26 May 2017
- CVE-2010-257279Bu hafta
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %59microsoft · powerpoint9 Kas 2010
- CVE-2006-249279Bu hafta
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allow
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %48microsoft · office19 May 2006
- CVE-2023-3301078Bu hafta
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %29zyxel · atp100 firmware24 May 2023
- CVE-2023-4106477Bu hafta
A buffer overflow issue was addressed with improved memory handling.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %53apple · ipados7 Eyl 2023
- CVE-2023-3300977Bu hafta
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %28zyxel · atp100 firmware24 May 2023
- CVE-2020-513577Bu hafta
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %27sonicwall · sonicos12 Eki 2020
- CVE-2016-009972Bu hafta
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %37microsoft · windows 10 15079 Mar 2016
- CVE-2020-1506972Bu hafta
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %11sophos · xg firewall firmware29 Haz 2020
- CVE-2013-064171Bu hafta
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %32adobe · acrobat13 Şub 2013
- CVE-2011-486268Bu hafta
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
KritikCVSS 10,0SilahlaştırılmışEPSS %95mit · krb5-appl24 Ara 2011
- CVE-2020-1198466Bu hafta
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
KritikCVSS 9,8Kavram kanıtıEPSS %90apache · http server7 Ağu 2020
- CVE-2021-371165Bu hafta
SM2 Decryption Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %88openssl · openssl24 Ağu 2021
- CVE-2009-302363Bu hafta
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to exe
KritikCVSS 9,0SilahlaştırılmışEPSS %91microsoft · internet information server31 Ağu 2009
- CVE-2004-021063Bu hafta
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly b
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %7microsoft · interix6 Ağu 2004
- CVE-2020-801262Bu hafta
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (c
KritikCVSS 9,8SilahlaştırılmışEPSS %77broadcom · unified infrastructure management18 Şub 2020