Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-14679HIGHPostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memoryEPSS 0.3%CVE-2019-25339MEDIUMGHIA CamIP 1.2 for iOS - 'Password' Denial of ServiceEPSS 0.3%CVE-2024-31803MEDIUMBuffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_frEPSS 0.3%CVE-2024-28568HIGHBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the rEPSS 0.3%CVE-2024-28567MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FEPSS 0.3%CVE-2024-7538HIGHoFono CUSD AT Command Stack-based Buffer Overflow Code Execution VulnerabilityEPSS 0.3%CVE-2025-44895MEDIUMFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.EPSS 0.3%CVE-2025-44892MEDIUMFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm functEPSS 0.3%CVE-2025-45514MEDIUMTenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.EPSS 0.3%CVE-2024-28573MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jEPSS 0.3%CVE-2025-52080MEDIUMIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoEPSS 0.3%CVE-2025-52082MEDIUMIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulneEPSS 0.3%CVE-2025-52081MEDIUMIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoEPSS 0.3%CVE-2024-47118MEDIUMIBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted queryEPSS 0.3%CVE-2025-47806MEDIUMIn GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to aEPSS 0.3%CVE-2023-29182MEDIUMA stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary codEPSS 0.3%CVE-2025-8472HIGHAlpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-5278MEDIUMCoreutils: heap buffer under-read in gnu coreutils sort via key specificationEPSS 0.3%CVE-2025-8475HIGHAlpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-41166MEDIUMStack-based buffer overflow in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an EPSS 0.3%