Weaknesses of type CWE-121

3,837 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-45841MEDIUMTOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg fuEPSS 0.5%CVE-2025-29217MEDIUMTenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability aEPSS 0.5%CVE-2024-14042MEDIUMOpen5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflowEPSS 0.5%CVE-2026-0206MEDIUMA post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.EPSS 0.5%CVE-2026-10192HIGHTenda W12 httpd set_local_time_0 stack-based overflowEPSS 0.5%CVE-2026-10189HIGHTenda W12 httpd cgiSysTimeInfoSet stack-based overflowEPSS 0.5%CVE-2024-53959HIGHAdobe Framemaker | Stack-based Buffer Overflow (CWE-121)EPSS 0.5%CVE-2023-3195—A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a EPSS 0.5%CVE-2024-27569MEDIUMLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerabilitEPSS 0.5%CVE-2024-27568MEDIUMLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerabEPSS 0.5%CVE-2024-23935HIGHAlpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-32311MEDIUMTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.EPSS 0.5%CVE-2026-10206HIGHD-Link DI-8400 dbsrv.asp stack-based overflowEPSS 0.5%CVE-2025-52292HIGHA stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) vEPSS 0.5%CVE-2025-29218MEDIUMTenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability alEPSS 0.5%CVE-2026-50031HIGHipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMEPSS 0.5%CVE-2023-51147HIGHBuffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary cEPSS 0.5%CVE-2023-51146HIGHBuffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via tEPSS 0.5%CVE-2024-43661HIGHBuffer overflow in <redacted>.so leads to DoS of OCPP serviceEPSS 0.5%CVE-2025-34165HIGHNetSupport Manager < 14.12.0000 Stack-Based Buffer OverflowEPSS 0.5%