Weaknesses of type CWE-121

3,847 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-70646HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allEPSS 0.4%CVE-2025-53593LOWQTS, QuTS heroEPSS 0.4%CVE-2025-71020HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability alEPSS 0.4%CVE-2023-36998HIGHThe NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in EPSS 0.4%CVE-2025-70651HIGHTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulEPSS 0.4%CVE-2025-70656HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows EPSS 0.4%CVE-2026-34122HIGHStack-based Buffer Overflow Leading to Denial of Service in TP-Link Tapo C520WSEPSS 0.4%CVE-2025-6663HIGHGStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2020-37142HIGH10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)EPSS 0.4%CVE-2024-41852HIGHAdobe Indesign 2024 AVI File Parsing Stack Based Buffer OverflowEPSS 0.4%CVE-2024-35333HIGHA stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper EPSS 0.4%CVE-2026-9216LOWInsufficient input validation vulnerability exists in certain NETGEAR RAX ModelsEPSS 0.4%CVE-2024-30273HIGHAdobe Illustrator 2024 PS file Parsing Stack based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-36600HIGHBuffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image fiEPSS 0.4%CVE-2026-24911HIGHStack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service.EPSS 0.4%CVE-2026-49789HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-7339MEDIUMData collection for dowloading leads into buffer overflowEPSS 0.4%CVE-2026-41681HIGHrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkEPSS 0.4%CVE-2020-37200MEDIUMNetShareWatcher 1.5.8.0 - 'Key' Denial of ServiceEPSS 0.4%CVE-2026-17259MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.4%