Weaknesses of type CWE-121

3,839 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-84351HIGHBuffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer procEPSS 0.4%CVE-2026-6665HIGHPgBouncer buffer overflow in SCRAMEPSS 0.4%CVE-2023-5407MEDIUMController denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security NotEPSS 0.4%CVE-2026-33447LOWCVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a EPSS 0.4%CVE-2024-35403LOWTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRuleEPSS 0.4%CVE-2017-12188—arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entrieEPSS 0.4%CVE-2023-6749HIGHUnchecked user input length in the Zephyr Settings ShellEPSS 0.4%CVE-2026-13086CRITICALFireware OS Stack-Based Buffer Overflow in Mobile Security epm EndpointEPSS 0.4%CVE-2026-88279MEDIUMGV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88283MEDIUMGV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88284MEDIUMGV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88281MEDIUMGV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of ServiceEPSS 0.4%CVE-2025-44899CRITICALThere is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGEPSS 0.4%CVE-2026-88280MEDIUMGV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2023-50268MEDIUMjq has stack-based buffer overflow in decNaNsEPSS 0.4%CVE-2019-25340MEDIUMSpotAuditor 5.3.2 - 'Base64' Denial Of ServiceEPSS 0.4%CVE-2026-35717MEDIUMA stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attEPSS 0.4%CVE-2025-26595HIGHXorg: xwayland: buffer overflow in xkbvmodmasktext()EPSS 0.4%CVE-2026-35716MEDIUMA stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attaEPSS 0.4%CVE-2026-10066HIGHShibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflowEPSS 0.4%