Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2023-48906MEDIUMStack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibbEPSS 0.3%CVE-2026-82079HIGHPotential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote AttackEPSS 0.3%CVE-2026-9038HIGHStack-based buffer overflow in XCharge C6EPSS 0.3%CVE-2026-12495MEDIUMStack-Based Buffer Overflow in the Mercusys MB115-4GEPSS 0.3%CVE-2024-7547HIGHoFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-8474MEDIUMAlpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2025-15150MEDIUMPX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflowEPSS 0.2%CVE-2025-9300MEDIUMsaitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflowEPSS 0.2%CVE-2020-36855MEDIUMDCMTK dcmqrscp parseQuota stack-based overflowEPSS 0.2%CVE-2024-32228MEDIUMFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.EPSS 0.2%CVE-2025-65220MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.EPSS 0.2%CVE-2025-47759HIGHV-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening sEPSS 0.2%CVE-2023-0123HIGHCVE-2023-0123EPSS 0.2%CVE-2025-47758HIGHV-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening EPSS 0.2%CVE-2024-29421MEDIUMxmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary cEPSS 0.2%CVE-2025-47760HIGHV-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening speciallEPSS 0.2%CVE-2022-3085HIGH Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attackEPSS 0.2%CVE-2021-31359HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerabilityEPSS 0.2%CVE-2025-11012MEDIUMBehaviorTree Diagnostic Message script_parser.cpp ParseScript stack-based overflowEPSS 0.2%CVE-2020-37132MEDIUMUltraVNC Launcher 1.2.4.0 - 'Password' Denial of ServiceEPSS 0.2%