Weaknesses of type CWE-121

3,847 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-41286HIGHStack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant BEPSS 0.3%CVE-2024-12185MEDIUMcode-projects Hotel Management System Administrator Login Password stack-based overflowEPSS 0.3%CVE-2024-37003HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2025-61498HIGHA buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying aEPSS 0.3%CVE-2026-5654MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2011-10021HIGHMagix Musik Maker <= v16 .mmm Stack-Based Buffer OverflowEPSS 0.3%CVE-2010-20114HIGHVariCAD EN <= 2010-2.05 .dwb File Stack Buffer OverflowEPSS 0.3%CVE-2010-20123HIGHSteinberg MyMP3Player <= 3.0.0.67 Buffer OverflowEPSS 0.3%CVE-2010-20042HIGHXion Audio Player ≤ 1.0.126 Unicode Stack Buffer OverflowEPSS 0.3%CVE-2009-20004HIGHgAlan <= 0.2.1 Buffer OverflowEPSS 0.3%CVE-2024-40412MEDIUMTenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.EPSS 0.3%CVE-2017-7936—A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DuEPSS 0.3%CVE-2026-13309MEDIUMAutel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2026-38752LOWA stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.3%CVE-2026-3081HIGHGStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2010-20045HIGHFileWrangler <= 5.30 Stack Buffer OverflowEPSS 0.3%CVE-2025-29118MEDIUMTenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.EPSS 0.3%CVE-2010-20010HIGHFoxit PDF Reader < 4.2.0.0928 Title Stack Buffer OverflowEPSS 0.3%CVE-2025-1366MEDIUMMicroWord eScan Antivirus VirusPopUp strcpy stack-based overflowEPSS 0.3%CVE-2026-24497HIGHStack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: fromEPSS 0.3%