Weaknesses of type CWE-121

3,839 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-13361HIGHIBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code ExecutionEPSS 0.5%CVE-2025-60333HIGHTOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig funcEPSS 0.5%CVE-2026-81532HIGHBI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionEPSS 0.5%CVE-2025-57087HIGHTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. ThEPSS 0.5%CVE-2025-57063HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function.EPSS 0.5%CVE-2025-57057HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulEPSS 0.5%CVE-2025-4472MEDIUMcode-projects Departmental Store Management System bill stack-based overflowEPSS 0.5%CVE-2025-57061HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, EPSS 0.5%CVE-2025-57058HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and EPSS 0.5%CVE-2025-57069HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnEPSS 0.5%CVE-2023-24334HIGHA stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary comEPSS 0.5%CVE-2025-57072HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute functioEPSS 0.5%CVE-2025-57059HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerabEPSS 0.5%CVE-2025-57071HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulneEPSS 0.5%CVE-2025-57062HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vEPSS 0.5%CVE-2025-57070HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulEPSS 0.5%CVE-2025-57060HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vEPSS 0.5%CVE-2025-2837HIGHSilicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-57064HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vEPSS 0.5%CVE-2026-89020MEDIUMMikroTik RouterOS Stack Buffer Overflow via TFTP URL PathEPSS 0.5%