Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-4038MEDIUMcode-projects Train Ticket Reservation System reservation stack-based overflowEPSS 0.3%CVE-2018-7514—Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prEPSS 0.3%CVE-2026-88388HIGHEspruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-EPSS 0.3%CVE-2026-16832HIGHPower System Buffer OverflowEPSS 0.3%CVE-2025-59383LOWMedia Streaming Add-onEPSS 0.3%CVE-2026-22320MEDIUMStack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIEPSS 0.3%CVE-2025-8404MEDIUMStack buffer overflow vulnerability exists in the Supermicro BMC Shared libraryEPSS 0.3%CVE-2025-58413MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, EPSS 0.3%CVE-2026-31267MEDIUMMercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overfEPSS 0.3%CVE-2019-25341MEDIUMiNetTools for iOS 8.20 - 'Whois' Denial of ServiceEPSS 0.3%CVE-2025-3196MEDIUMOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflowEPSS 0.3%CVE-2025-49564HIGHIllustrator | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-21224HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-27590HIGHRizin has stack-based buffer overflow when parsing GDB registers profile filesEPSS 0.3%CVE-2019-25434MEDIUMSpotAuditor 5.3.1.0 Denial of Service via Registration Name FieldEPSS 0.3%CVE-2024-23797HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2024-51473MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2019-25062MEDIUMSricam IP CCTV Camera Device Viewer stack-based overflowEPSS 0.3%CVE-2024-23798HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2023-46273HIGHBonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_sEPSS 0.3%