Weaknesses of type CWE-121

3,834 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-5245MEDIUMCesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflowEPSS 0.6%CVE-2024-44859HIGHTenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.EPSS 0.6%CVE-2026-27671CRITICALMemory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP PlatformEPSS 0.6%CVE-2023-4601HIGHStack-based Buffer Overflow in NI System Configuration SoftwareEPSS 0.6%CVE-2025-60331HIGHD-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This EPSS 0.6%CVE-2026-44859HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44858HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44856HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44857HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44855HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-81480HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged atEPSS 0.6%CVE-2026-0719HIGHLibsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationEPSS 0.6%CVE-2024-33516MEDIUMAn unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. SucEPSS 0.6%CVE-2024-31163HIGHASUS Download Master - Buffer OverflowEPSS 0.6%CVE-2025-29100CRITICALTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.EPSS 0.6%CVE-2024-33514MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.6%CVE-2024-27656HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cauEPSS 0.6%CVE-2024-33517MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. SucceEPSS 0.6%CVE-2024-46049MEDIUMTenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.EPSS 0.6%CVE-2024-46044MEDIUMCH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.EPSS 0.6%