Weaknesses of type CWE-121

3,840 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2024-34944HIGHTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhEPSS 0.4%CVE-2022-34667MEDIUMNVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploEPSS 0.4%CVE-2024-30293HIGHAdobe Animate 2024 AI File parsing Stack base buffer overflow Remote Code execution VulnerabilityEPSS 0.4%CVE-2025-60342HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability aEPSS 0.4%CVE-2025-60661MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.EPSS 0.4%CVE-2023-26337HIGHZDI-CAN-20285: Adobe Dimension USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-71407MEDIUMA Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attEPSS 0.4%CVE-2024-35276MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer EPSS 0.4%CVE-2025-51082MEDIUMTenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZEPSS 0.4%CVE-2025-59365MEDIUMA stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerabilityEPSS 0.4%CVE-2025-36097HIGHIBM WebSphere Application Server denial of serviceEPSS 0.4%CVE-2025-60566HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.EPSS 0.4%CVE-2026-42919HIGHF5 BIG-IP Appliance Mode VulnerabilityEPSS 0.4%CVE-2022-26873HIGHThe stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.EPSS 0.4%CVE-2026-40950HIGHBuffer overflow in the Secure Access server prior to 14.50EPSS 0.4%CVE-2024-23126HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2024-30636MEDIUMTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.EPSS 0.4%CVE-2024-35579HIGHTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.EPSS 0.4%CVE-2025-50260HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.EPSS 0.4%CVE-2010-20111HIGHDigital Music Pad <= 8.2.3.3.4 Stack Buffer OverflowEPSS 0.4%