Weaknesses of type CWE-121

3,851 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-21068HIGHStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.EPSS 0.2%CVE-2022-34401HIGH Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiEPSS 0.2%CVE-2025-70309MEDIUMA stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAEPSS 0.2%CVE-2026-5726HIGHASDA-Soft Stack-based Buffer Overflow VulnerabilityEPSS 0.2%CVE-2026-12150HIGHIBM MQ queue manager is vulnerable to denial of serviceEPSS 0.2%CVE-2025-12464MEDIUMQemu-kvm: stack buffer overflow in e1000 device via short frames in loopback modeEPSS 0.2%CVE-2026-8356MEDIUMStack buffer overflow in PPT presentation importEPSS 0.2%CVE-2022-34403HIGH Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerabilityEPSS 0.2%CVE-2025-20718HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.2%CVE-2026-16945HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2025-32058CRITICALStack Overflow in processing requests over INC interface on RH850 side of Infotainment ECUEPSS 0.2%CVE-2026-81946MEDIUMPLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 AlgorithmEPSS 0.2%CVE-2025-55095MEDIUMThe function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters anEPSS 0.2%CVE-2024-41170HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (AllEPSS 0.2%CVE-2025-20618HIGHStack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user toEPSS 0.2%CVE-2025-64469HIGHStack-based Buffer Overflow in LVResource::DetachResource() in NI LabVIEWEPSS 0.2%CVE-2026-12661MEDIUMFactoryTalk® Historian Machine Edition - Out-of-Bounds Write VulnerabilityEPSS 0.2%CVE-2026-36907MEDIUMA stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of EPSS 0.2%CVE-2023-44178MEDIUMJunos OS : Stack overflow vulnerability in CLI command processingEPSS 0.2%CVE-2025-40741HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based oEPSS 0.2%