Weaknesses of type CWE-121

3,825 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-75877CRITICALTRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflowEPSS 0.9%CVE-2026-13518HIGHTenda JD12L addressNat fromAddressNat stack-based overflowEPSS 0.9%CVE-2026-16248HIGHTenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflowEPSS 0.9%CVE-2026-19815HIGHTOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflowEPSS 0.9%CVE-2026-19813HIGHTOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflowEPSS 0.9%CVE-2026-19824HIGHTenda W20E addIpMacBind ipMacBindListStore stack-based overflowEPSS 0.9%CVE-2026-19847HIGHTOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflowEPSS 0.9%CVE-2026-19845HIGHTOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflowEPSS 0.9%CVE-2026-19822HIGHTenda W20E QoS Edit editQos lstAdd stack-based overflowEPSS 0.9%CVE-2026-13515HIGHTenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflowEPSS 0.9%CVE-2024-37044MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2026-61674CRITICALFluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handlerEPSS 0.9%CVE-2026-13539HIGHWavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflowEPSS 0.9%CVE-2026-76589CRITICALTRENDnet TEW-755AP mycli FUN_401000 stack-based overflowEPSS 0.9%CVE-2026-19790HIGHTenda G0 httpd Web Management module formSetPortMirror stack-based overflowEPSS 0.9%CVE-2026-13519HIGHTenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflowEPSS 0.9%CVE-2026-15691HIGHTenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflowEPSS 0.9%CVE-2026-19788HIGHTenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflowEPSS 0.9%CVE-2026-82616CRITICALTOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflowEPSS 0.9%CVE-2026-15694HIGHTenda BE12 Pro SetIpBind fromSetIpBind stack-based overflowEPSS 0.9%