Weaknesses of type CWE-121

3,848 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-54274HIGHSubstance3D - Viewer | Stack-based Buffer Overflow (CWE-121)EPSS 0.2%CVE-2026-96676MEDIUMFast FAC1900R uhttpd get_alias_name stack-based overflowEPSS 0.2%CVE-2025-68622MEDIUMEspressif ESP-IDF USB Host UVC Class Driver has a stack buffer overflow in UVC descriptor printingEPSS 0.2%CVE-2020-13598MEDIUMFS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_statEPSS 0.2%CVE-2024-1598HIGHPotential buffer overflow when handling UEFI variablesEPSS 0.2%CVE-2023-27914HIGHA maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack EPSS 0.2%CVE-2024-46325MEDIUMTP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.EPSS 0.2%CVE-2024-34085HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), TeamceEPSS 0.2%CVE-2026-18297HIGHGStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2024-7784MEDIUMDuring internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly kEPSS 0.2%CVE-2026-3137MEDIUMCodeAstro Food Ordering System food_ordering.exe stack-based overflowEPSS 0.2%CVE-2023-42463HIGHwazuh-logcollector integer underflow local privilege escalationEPSS 0.2%CVE-2024-23594MEDIUM A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operatiEPSS 0.2%CVE-2024-52572HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-37008HIGHStack-based Overflow Vulnerability in Revit SoftwareEPSS 0.2%CVE-2025-65410MEDIUMA stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a craftEPSS 0.2%CVE-2023-35012MEDIUMIBM Db2 code executionEPSS 0.2%CVE-2025-70616HIGHA stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for codEPSS 0.2%CVE-2020-9253MEDIUMThere is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit this vulnerability. DueEPSS 0.2%CVE-2026-25502HIGHiccDEV is vulnerable to stack-buffer-overflow in icFixXml()EPSS 0.2%