Weaknesses of type CWE-121

3,820 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-7090HIGHBelkin F9K1122 webs formConnectionSetting stack-based overflowEPSS 5.3%CVE-2025-7093HIGHBelkin F9K1122 webs formSetLanguage stack-based overflowEPSS 5.3%CVE-2025-7089HIGHBelkin F9K1122 webs formWanTcpipSetup stack-based overflowEPSS 5.3%CVE-2025-7092HIGHBelkin F9K1122 webs formWlanSetupWPS stack-based overflowEPSS 5.3%CVE-2017-3223Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflowEPSS 5.3%CVE-2024-36729MEDIUMTRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated usEPSS 5.3%CVE-2017-12194A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-serEPSS 5.2%CVE-2019-3922The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST reEPSS 5.2%CVE-2014-9189Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior tEPSS 5.2%CVE-2018-17910WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow cEPSS 5.2%CVE-2024-36728HIGHTRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated usEPSS 5.2%CVE-2025-9605CRITICALTenda AC21/AC23 GetParentControlInfo stack-based overflowEPSS 5.1%CVE-2025-28144MEDIUMEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin paramEPSS 5.1%CVE-2025-7086HIGHBelkin F9K1122 webs formPPTPSetup stack-based overflowEPSS 5.0%CVE-2022-4634HIGHCVE-2022-4634EPSS 4.9%CVE-2022-20711CRITICALCisco Small Business RV Series Routers VulnerabilitiesEPSS 4.9%CVE-2020-7065HIGHmb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_fullEPSS 4.9%CVE-2025-9299HIGHTenda M3 getMasterPassengerAnalyseData formGetMasterPassengerAnalyseData stack-based overflowEPSS 4.9%CVE-2025-68706CRITICALA stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMulEPSS 4.9%CVE-2025-45867MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interfaEPSS 4.9%