Weaknesses of type CWE-121

3,827 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2025-7550HIGHTenda FH1201 GstDhcpSetSer fromGstDhcpSetSer stack-based overflowEPSS 0.8%CVE-2025-7421HIGHTenda O3V2 httpd operateMacFilter fromMacFilterModify stack-based overflowEPSS 0.8%CVE-2025-7422HIGHTenda O3V2 httpd setNetworkService setAutoReboot stack-based overflowEPSS 0.8%CVE-2025-7597HIGHTenda AX1803 setMacFilterCfg formSetMacFilterCfg stack-based overflowEPSS 0.8%CVE-2025-7420HIGHTenda O3V2 httpd setWrlBasicInfo formWifiBasicSet stack-based overflowEPSS 0.8%CVE-2025-7596HIGHTenda FH1205 WifiExtraSet formWifiExtraSet stack-based overflowEPSS 0.8%CVE-2025-7416HIGHTenda O3V2 httpd setSysTimeInfo fromSysToolTime stack-based overflowEPSS 0.8%CVE-2025-7598HIGHTenda AX1803 setWifiFilterCfg formSetWifiMacFilterCfg stack-based overflowEPSS 0.8%CVE-2024-23959HIGHAutel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-33835CRITICALTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.EPSS 0.8%CVE-2023-36950HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_hoEPSS 0.8%CVE-2023-36947HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File paEPSS 0.8%CVE-2025-7528HIGHTenda FH1202 GstDhcpSetSer fromGstDhcpSetSer stack-based overflowEPSS 0.8%CVE-2025-7527HIGHTenda FH1202 AdvSetWan fromAdvSetWan stack-based overflowEPSS 0.8%CVE-2025-7529HIGHTenda FH1202 Natlimit fromNatlimit stack-based overflowEPSS 0.8%CVE-2025-7530HIGHTenda FH1202 PPTPDClient fromPptpUserAdd stack-based overflowEPSS 0.8%CVE-2021-36193MEDIUMMultiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achievEPSS 0.8%CVE-2026-20797MEDIUMCopeland XWEB and XWEB Pro Stack-based Buffer OverflowEPSS 0.8%CVE-2025-8060HIGHTenda AC23 httpd setMacFilterCfg sub_46C940 stack-based overflowEPSS 0.8%CVE-2023-27355HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. AuEPSS 0.8%