Weaknesses of type CWE-121

3,849 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-39853HIGHosslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature VerificationEPSS 0.2%CVE-2023-21414HIGHNCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (EPSS 0.2%CVE-2026-32925HIGHV-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 filEPSS 0.2%CVE-2026-32928HIGHV-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 fEPSS 0.2%CVE-2023-51792LOWBuffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding theEPSS 0.2%CVE-2025-5555HIGHNixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflowEPSS 0.2%CVE-2025-7704MEDIUMSupermicro BMC SMASH services has a Stack-based buffer overflow vulnerabilityEPSS 0.2%CVE-2025-60696HIGHA stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012)EPSS 0.2%CVE-2025-60692HIGHA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001EPSS 0.2%CVE-2024-33577HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerabilEPSS 0.2%CVE-2023-4685HIGHCVE-2023-4685EPSS 0.2%CVE-2023-29503HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a sEPSS 0.2%CVE-2023-37374HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2023-37375HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2026-86054HIGHNotepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session pathEPSS 0.2%CVE-2023-45601HIGHA vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1.250), Parasolid V36EPSS 0.2%CVE-2024-31496MEDIUMA stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer vEPSS 0.2%CVE-2025-34450MEDIUMmerbanan/rtl_433 <= 25.02 Stack-based Buffer OverflowEPSS 0.2%CVE-2022-36337HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration drivEPSS 0.2%CVE-2022-47936HIGHA vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Parasolid V34.0 (All verEPSS 0.2%