Weaknesses of type CWE-121

3,850 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2022-47936HIGHA vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Parasolid V34.0 (All verEPSS 0.2%CVE-2025-9820MEDIUMGnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() functionEPSS 0.2%CVE-2025-7979HIGHAshlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-85279HIGHNotepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return ValueEPSS 0.2%CVE-2023-38581HIGHBuffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation EPSS 0.2%CVE-2025-15155MEDIUMfloooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflowEPSS 0.2%CVE-2023-53879MEDIUMNVClient 5.0 Stack Buffer Overflow Vulnerability via User ConfigurationEPSS 0.2%CVE-2026-14789MEDIUMradareorg radare2 Memory64ListStream mdmp.c stack-based overflowEPSS 0.2%CVE-2025-41388HIGHFuji Electric Smart Editor Stack-based Buffer OverflowEPSS 0.2%CVE-2025-60685MEDIUMA stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function).EPSS 0.2%CVE-2025-60686MEDIUMA local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.61EPSS 0.2%CVE-2026-50259HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexingEPSS 0.2%CVE-2026-50258HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levelsEPSS 0.2%CVE-2024-43032MEDIUMautMan v2.9.6 allows attackers to bypass authentication via a crafted web request.EPSS 0.2%CVE-2026-25584HIGHiccDEV vulnerable to Stack-based Buffer Overflow in CIccTagFloatNum::GetValues()EPSS 0.2%CVE-2019-25336HIGHSpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)EPSS 0.2%CVE-2023-30900HIGHA vulnerability has been identified in Xpedition Layout Browser (All versions < VX.2.14). Affected application contains a stack overflow vulEPSS 0.2%CVE-2024-21758MEDIUMA stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execEPSS 0.2%CVE-2023-24566LOWA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (AEPSS 0.2%CVE-2025-70305MEDIUMA stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.EPSS 0.2%