Weaknesses of type CWE-121

3,833 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2017-16332HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16310HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16275HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16335HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16308HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16278HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2026-51807CRITICALHeap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caEPSS 0.7%CVE-2024-37634CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.EPSS 0.7%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 0.7%CVE-2026-59837MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2,EPSS 0.7%CVE-2020-37138HIGH10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)EPSS 0.7%CVE-2024-30612HIGHTenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState funcEPSS 0.7%CVE-2025-60679HIGHA stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cEPSS 0.7%CVE-2025-40634CRITICALStack-based buffer overflow in TP-Link Archer AX50EPSS 0.7%CVE-2026-58181HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crashEPSS 0.7%CVE-2024-30394HIGHJunos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crashEPSS 0.7%CVE-2026-58180HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker inputEPSS 0.7%CVE-2025-14423HIGHGIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-37635CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfgEPSS 0.7%CVE-2026-67379HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.7%