Weaknesses of type CWE-121

3,851 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-29988MEDIUMDell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentialEPSS 0.2%CVE-2026-71266HIGHtinyobjloader-c Stack Buffer Overflow in MTL Material File Line ParsingEPSS 0.2%CVE-2026-34542MEDIUMiccDEV: SBO in CIccCalculatorFunc::Apply()EPSS 0.2%CVE-2026-83962HIGHSubstance3D - Modeler | Stack-based Buffer Overflow (CWE-121)EPSS 0.2%CVE-2026-29628MEDIUMA stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of ServiceEPSS 0.2%CVE-2026-13573MEDIUMllvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflowEPSS 0.2%CVE-2026-4015MEDIUMGPAC TeXML File load_text.c txtin_process_texml stack-based overflowEPSS 0.2%CVE-2020-37001HIGHFrigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)EPSS 0.2%CVE-2024-3100MEDIUMA potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privEPSS 0.2%CVE-2026-15167HIGHStack-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-8258MEDIUMSquirrel sqstdstring.cpp validate_format stack-based overflowEPSS 0.2%CVE-2026-15419HIGHCP210x Driver Memory Corruption results in Arbitrary Code ExecutionEPSS 0.2%CVE-2024-37997HIGHA vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0EPSS 0.2%CVE-2020-36965HIGHdocPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)EPSS 0.2%CVE-2026-91090LOWGPAC base_scenegraph.c gf_node_activate_ex stack-based overflowEPSS 0.2%CVE-2026-17093HIGHPower System Buffer OverflowEPSS 0.2%CVE-2025-1253MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-17494HIGHPower System Buffer OverflowEPSS 0.2%CVE-2026-19234HIGHPower System Buffer OverflowEPSS 0.2%CVE-2025-12464MEDIUMQemu-kvm: stack buffer overflow in e1000 device via short frames in loopback modeEPSS 0.2%