Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-6791MEDIUMPotential stack-based buffer clash during tilde expansion in wordexpEPSS 0.3%CVE-2026-81738LOWOpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEPSS 0.3%CVE-2025-55117MEDIUMBMC Control-M/Agent buffer overflow in SSL/TLS communicationEPSS 0.3%CVE-2025-1164MEDIUMcode-projects Police FIR Record Management System Add Record stack-based overflowEPSS 0.3%CVE-2023-6693MEDIUMQemu: virtio-net: stack buffer overflow in virtio_net_flush_tx()EPSS 0.3%CVE-2025-28344HIGHstriso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.EPSS 0.3%CVE-2025-28343HIGHstriso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.EPSS 0.3%CVE-2024-41590HIGHSeveral CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed thEPSS 0.3%CVE-2024-37029HIGHFuji Electric Tellus Lite V-Simulator Stack-based Buffer OverflowEPSS 0.3%CVE-2019-25328MEDIUMXnConvert 1.82 - Denial of ServiceEPSS 0.3%CVE-2025-8653HIGHKenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2019-25330MEDIUMSurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH)EPSS 0.3%CVE-2025-1187MEDIUMcode-projects Police FIR Record Management System Delete Record stack-based overflowEPSS 0.3%CVE-2026-62655MEDIUMA DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi modelsEPSS 0.3%CVE-2026-32743MEDIUMPX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request HandlingEPSS 0.3%CVE-2025-45862MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interEPSS 0.3%CVE-2025-54617MEDIUMStack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.EPSS 0.3%CVE-2022-41664HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamceEPSS 0.3%CVE-2024-35576MEDIUMTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.EPSS 0.3%CVE-2026-12200MEDIUMRitlabs TinyWeb Server Header libeay32.dll.html stack-based overflowEPSS 0.3%