Weaknesses of type CWE-121

3,840 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2024-32317HIGHTenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSEPSS 0.4%CVE-2026-27821HIGHGPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer OverflowEPSS 0.4%CVE-2024-32316MEDIUMTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.EPSS 0.4%CVE-2024-33213MEDIUMTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goEPSS 0.4%CVE-2026-57163HIGHPJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backendEPSS 0.4%CVE-2024-40417MEDIUMA vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBinEPSS 0.4%CVE-2012-10051HIGHPhotodex ProShow Producer 5.0.3256 load File Handling Buffer OverflowEPSS 0.4%CVE-2026-10064MEDIUMTRENDnet TEW-432BRP formSetPortTr stack-based overflowEPSS 0.4%CVE-2023-38094HIGHKofax Power PDF replacePages Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38092HIGHKofax Power PDF importDataObject Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-47410HIGHAnimate | Stack-based Buffer Overflow (CWE-121)EPSS 0.4%CVE-2023-38093HIGHKofax Power PDF saveAs Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-3729LOWRSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Buffer Overflow vulnerEPSS 0.4%CVE-2024-49350MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2025-32061HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2023-46272HIGHBuffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute EPSS 0.4%CVE-2012-10043CRITICALActFax 4.32 Client Importer Buffer OverflowEPSS 0.4%CVE-2026-49943MEDIUMCZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation inEPSS 0.4%CVE-2023-40484HIGHMaxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-32062HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%