Weaknesses of type CWE-121

3,820 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2022-20825CRITICALCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilityEPSS 3.2%CVE-2026-10179HIGHTRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflowEPSS 3.2%CVE-2022-26002CRITICALA stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-cEPSS 3.2%CVE-2017-12706A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiEPSS 3.2%CVE-2018-17911LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution.EPSS 3.2%CVE-2023-42116HIGHExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 3.2%CVE-2018-14807A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow reEPSS 3.1%CVE-2018-5440A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based COEPSS 3.1%CVE-2025-7795HIGHTenda FH451 P2pListFilter fromP2pListFilter stack-based overflowEPSS 3.1%CVE-2023-35744HIGHD-Link DAP-2622 DDP Configuration Restore Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 3.1%CVE-2018-10839MEDIUMQemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflowEPSS 3.1%CVE-2022-20712CRITICALCisco Small Business RV Series Routers VulnerabilitiesEPSS 3.0%CVE-2020-25159Real Time Automation EtherNet/IPEPSS 3.0%CVE-2012-10060CRITICALSysax Multi Server < 5.55 SSH Username Buffer OverflowEPSS 3.0%CVE-2021-21891CRITICALA stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (iEPSS 3.0%CVE-2021-21890CRITICALA stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (iEPSS 3.0%CVE-2021-21887CRITICALA stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (EPSS 3.0%CVE-2019-13520Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafEPSS 2.9%CVE-2020-2501Stack Buffer Overflow in Surveillance StationEPSS 2.9%CVE-2019-14897MEDIUMA stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to causEPSS 2.9%