Weaknesses of type CWE-121

3,851 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-21093MEDIUMStack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memorEPSS 0.1%CVE-2024-39556HIGHJunos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflowEPSS 0.1%CVE-2025-53175MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-53172MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-53174MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58301MEDIUMBuffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-53171MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2024-58117MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58300MEDIUMBuffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-58295MEDIUMBuffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-58297MEDIUMBuffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-21807LOWHCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflowEPSS 0.1%CVE-2025-53176LOWStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58298HIGHData processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-44448MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-38672MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%CVE-2025-47347HIGHStack-based Buffer Overflow in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-20797HIGHIn battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%CVE-2025-20747MEDIUMIn gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege EPSS 0.1%CVE-2025-20749MEDIUMIn charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%