Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-62877HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50412HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-48715HIGHradvdump's Route Information Option Parser has a Stack Buffer OverflowEPSS 0.3%CVE-2026-50400HIGHWindows App Package Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70344HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50318HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-83990HIGHMicrosoft Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69467HIGHMicrosoft Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-66877HIGHBuffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.EPSS 0.3%CVE-2026-69391HIGHWindows Broker Infrastructure Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69290HIGHWindows Storage Spaces Controller Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-71337HIGHWindows Storage Management Provider Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62768HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2019-25435HIGHSricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP BypassEPSS 0.3%CVE-2026-57091HIGHWindows File History Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-40399HIGHWindows TCP/IP Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-40201HIGHBentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed desigEPSS 0.3%CVE-2026-10898HIGHStack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2026-6791MEDIUMPotential stack-based buffer clash during tilde expansion in wordexpEPSS 0.3%CVE-2026-81738LOWOpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEPSS 0.3%