Weaknesses of type CWE-121

3,834 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-75126MEDIUMPLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Standard HandlersEPSS 0.6%CVE-2025-53009MEDIUMMaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion LimitEPSS 0.6%CVE-2026-1361HIGHASDA-Soft Stack-based Buffer Overflow VulnerabilityEPSS 0.6%CVE-2026-77217MEDIUMPLANET GS-4210-16P2S V3 Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi RADIUS HandlersEPSS 0.6%CVE-2025-70244HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.EPSS 0.6%CVE-2025-70251HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.EPSS 0.6%CVE-2026-12846CRITICALGeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET commandEPSS 0.6%CVE-2026-12847CRITICALGeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET commandEPSS 0.6%CVE-2024-51314CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.EPSS 0.6%CVE-2026-59144CRITICALData::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seqEPSS 0.6%CVE-2026-19341HIGHUTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflowEPSS 0.6%CVE-2026-12485CRITICALGeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET commandEPSS 0.6%CVE-2024-51311CRITICALThe Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.EPSS 0.6%CVE-2026-75783CRITICALTRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflowEPSS 0.6%CVE-2024-51315CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevNameEPSS 0.6%CVE-2026-12848CRITICALGeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET commandEPSS 0.6%CVE-2024-51312CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.EPSS 0.6%CVE-2024-51313CRITICALThe Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.EPSS 0.6%CVE-2026-41509MEDIUMInteger underflow in crypto_sign_open() leads to buffer overflowEPSS 0.6%CVE-2026-40892HIGHPJSIP: Stack buffer overflow in pjsip_auth_create_digest2()EPSS 0.6%