Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-34690HIGHAfter Effects | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2019-10974—NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten wiEPSS 0.3%CVE-2026-34697HIGHInDesign Desktop | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-27267HIGHIllustrator | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-47971HIGHMedia Encoder | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2009-20003HIGHXenorate <= 2.50 .xpl File Stack-Based Buffer OverflowEPSS 0.3%CVE-2026-18681MEDIUMThis Power System Buffer OverflowEPSS 0.3%CVE-2026-12488MEDIUMGeoVision GV-VMS V20 GV-Cloud memory corruption vulnerabilityEPSS 0.3%CVE-2025-8076HIGHA stack buffer overflow vulnerability exists in the Supermicro BMC Web functionEPSS 0.3%CVE-2025-8727HIGHA stack buffer overflow vulnerability exists in the Supermicro BMC Web function(SSL).EPSS 0.3%CVE-2025-46405HIGHBIG-IP APM vulnerabilityEPSS 0.3%CVE-2025-67432HIGHA stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of EPSS 0.3%CVE-2026-0399MEDIUMMultiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checkingEPSS 0.3%CVE-2024-25331CRITICALDIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (REPSS 0.3%CVE-2026-67560HIGHStack-based Buffer Overflow in Bendix EC80 Brake ECUEPSS 0.3%CVE-2026-62755HIGHWindows DHCP Client Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62877HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69290HIGHWindows Storage Spaces Controller Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69467HIGHMicrosoft Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70346HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%