Weaknesses of type CWE-121

3,840 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-50260HIGHTenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.EPSS 0.4%CVE-2020-36997HIGHBacklinkSpeed 2.4 - Buffer Overflow PoC (SEH)EPSS 0.4%CVE-2024-27337HIGHKofax Power PDF TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-7509HIGHTrimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-11541CRITICALStack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programEPSS 0.4%CVE-2025-11542HIGHStack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programEPSS 0.4%CVE-2023-26412HIGHZDI-CAN-20314: Adobe Substance 3D Designer USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-48725LOWQuTS heroEPSS 0.4%CVE-2023-29284HIGHZDI-CAN-20365: Adobe Substance 3D Painter USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26383HIGHZDI-CAN-20287: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-43718MEDIUMA stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TahEPSS 0.4%CVE-2024-11262MEDIUMSourceCodester Student Record Management System View All Student Marks main stack-based overflowEPSS 0.4%CVE-2023-26390HIGHZDI-CAN-20255: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-4156HIGHChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2020-37198MEDIUMDuplicate Cleaner Pro 4 - Denial of ServiceEPSS 0.4%CVE-2026-3697MEDIUMPlanet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflowEPSS 0.4%CVE-2022-33213HIGHMemory Corruption in MODEMEPSS 0.4%CVE-2026-88268MEDIUMGV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of ServiceEPSS 0.4%CVE-2026-88408MEDIUMFalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). ThiEPSS 0.4%CVE-2025-59362MEDIUMSquid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.EPSS 0.4%