Weaknesses of type CWE-121

3,851 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2020-37221HIGHAtomic Alarm Clock 6.3 Stack Overflow via SEH UnicodeEPSS 0.2%CVE-2019-25331HIGHAVS Audio Converter 9.1 - 'Exit folder' Buffer OverflowEPSS 0.2%CVE-2026-41434LOWOP-TEE has unbounded recursion in sanitize_client_object()EPSS 0.2%CVE-2025-15013MEDIUMfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflowEPSS 0.1%CVE-2026-11979LOWStack-Based Buffer Overflow in libxml2EPSS 0.1%CVE-2026-7260MEDIUMStack overflow in phar with circular symlinksEPSS 0.1%CVE-2026-25570HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values EPSS 0.1%CVE-2025-9336MEDIUMA stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading EPSS 0.1%CVE-2018-25322HIGHAllok Fast AVI MPEG Splitter 1.2 Stack Based Buffer OverflowEPSS 0.1%CVE-2026-42050MEDIUMImageMagick: Stack buffer overflow in XTileImageEPSS 0.1%CVE-2026-47318MEDIUMStack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b3EPSS 0.1%CVE-2025-20738MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-49014HIGHIn GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reaEPSS 0.1%CVE-2025-20739MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-81546HIGHThe Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity documEPSS 0.1%CVE-2025-20737HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2025-29951HIGHA buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privileEPSS 0.1%CVE-2024-31203LOWA “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attackeEPSS 0.1%CVE-2022-39116MEDIUMIn sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service inEPSS 0.1%CVE-2026-33963HIGHAn issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffeEPSS 0.1%