Weaknesses of type CWE-121

3,839 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-28030HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRulEPSS 0.5%CVE-2024-32306MEDIUMTenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.EPSS 0.5%CVE-2025-70250HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.EPSS 0.5%CVE-2026-101037CRITICALFAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflowEPSS 0.5%CVE-2025-26386HIGHStack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) toolEPSS 0.5%CVE-2026-22214MEDIUMRIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame ParserEPSS 0.5%CVE-2026-16418HIGHStack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.5%CVE-2026-78910HIGHBuffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a cEPSS 0.5%CVE-2026-68516MEDIUMOpenEXR: HTJ2K SIZ image-offset gap stack buffer overflowEPSS 0.5%CVE-2025-70746HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime function. This vulnerabiliEPSS 0.5%CVE-2026-57165MEDIUMPJSIP: Pre-authentication overflow in the telnet CLI historyEPSS 0.5%CVE-2024-3286HIGH A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restartEPSS 0.5%CVE-2024-52273HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2024-52272HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2025-34124HIGHHeroes of Might and Magic III .h3m Map File Buffer OverflowEPSS 0.4%CVE-2024-52274HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2024-25137MEDIUMAutomationDirect C-MORE EA9 HMI Stack-based Buffer OverflowEPSS 0.4%CVE-2026-63387HIGHLibevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server responseEPSS 0.4%CVE-2025-71021HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability EPSS 0.4%CVE-2024-5931MEDIUMBT: Unchecked user input in bap_broadcast_assistantEPSS 0.4%