Weaknesses of type CWE-121

3,839 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-17138HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2025-1163MEDIUMcode-projects Vehicle Parking Management System Authentication login stack-based overflowEPSS 0.5%CVE-2026-68863HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with reEPSS 0.5%CVE-2023-0426HIGHStack overflow in filename or in boundary EPSS 0.5%CVE-2026-11553HIGHTenda HG7HG9/HG10 formPPPEdit stack-based overflowEPSS 0.5%CVE-2024-49537HIGHAfter Effects | Stack-based Buffer Overflow (CWE-121)EPSS 0.5%CVE-2024-20524MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Denial of Service VulnerabilitiesEPSS 0.5%CVE-2019-16470HIGHCoolType.dll crash - Tianfu CupEPSS 0.5%CVE-2026-11557HIGHTenda F451 Web Management Natlimit fromNatlimit stack-based overflowEPSS 0.5%CVE-2026-10191HIGHTenda W12 httpd cgiWifiMacFilterSet stack-based overflowEPSS 0.5%CVE-2024-20523MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Denial of Service VulnerabilitiesEPSS 0.5%CVE-2026-10188HIGHTenda W12 httpd cgistaKickOff stack-based overflowEPSS 0.5%CVE-2025-64096HIGHCryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length checkEPSS 0.5%CVE-2025-66176HIGHThere is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an aEPSS 0.5%CVE-2025-29149HIGHTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.EPSS 0.5%CVE-2025-29121HIGHA vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file fEPSS 0.5%CVE-2025-29101HIGHTenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info functionEPSS 0.5%CVE-2021-47789MEDIUMYenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)EPSS 0.5%CVE-2026-10161HIGHTRENDnet TEW-432BRP formResetStatistic stack-based overflowEPSS 0.5%CVE-2026-10829HIGHA stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerabiliEPSS 0.5%