Weaknesses of type CWE-121

3,851 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2022-42270HIGHNVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause EPSS 0.2%CVE-2025-58775HIGHKV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary codEPSS 0.2%CVE-2026-5525MEDIUMStack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoSEPSS 0.2%CVE-2026-30980MEDIUMiccDEV has a stack overflow in CIccBasicStructFactory::CreateStruct()EPSS 0.2%CVE-2025-58776HIGHKV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrEPSS 0.2%CVE-2018-25375HIGHSocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEHEPSS 0.2%CVE-2018-25373HIGHDVD Photo Slideshow Professional 8.07 Buffer Overflow SEHEPSS 0.2%CVE-2018-25383HIGHFree MP3 CD Ripper 2.8 Buffer Overflow SEH DEP BypassEPSS 0.2%CVE-2025-4425HIGHSetupAutomationSmm: Stack overflow vulnerability in SMI handlerEPSS 0.2%CVE-2024-46663MEDIUMA stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged aEPSS 0.2%CVE-2025-8851MEDIUMLibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflowEPSS 0.2%CVE-2026-90824MEDIUMGPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflowEPSS 0.2%CVE-2025-25066HIGHnDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.EPSS 0.2%CVE-2026-43771HIGHA stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2025-54526HIGHFuji Electric Monitouch V-SFT-6 Stack-based Buffer OverflowEPSS 0.2%CVE-2020-36971HIGHNidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer OverflowEPSS 0.2%CVE-2024-53041HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2020-37128MEDIUMZOC Terminal 7.25.5 - 'Script' Denial of ServiceEPSS 0.2%CVE-2026-43958HIGHRrdtool: rrdtool: stack buffer overflow allows local code execution or denial of serviceEPSS 0.2%CVE-2026-71266HIGHtinyobjloader-c Stack Buffer Overflow in MTL Material File Line ParsingEPSS 0.2%