Weaknesses of type CWE-121

3,827 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-4167HIGHBelkin F9K1122 formReboot stack-based overflowEPSS 0.8%CVE-2026-9425HIGHEdimax EW-7438RPn formWlanMP stack-based overflowEPSS 0.8%CVE-2026-9480HIGHEdimax EW-7438RPn formrefresh stack-based overflowEPSS 0.8%CVE-2026-9459HIGHEdimax EW-7438RPn formConnectionSetting stack-based overflowEPSS 0.8%CVE-2026-9463HIGHEdimax EW-7438RPn formLicence stack-based overflowEPSS 0.8%CVE-2026-19959CRITICALEdimax EW-7478APC formWanTcpipSetup stack-based overflowEPSS 0.8%CVE-2026-13563HIGHEdimax EW-7478APC POST Request formL2TPSetup stack-based overflowEPSS 0.8%CVE-2026-9427HIGHEdimax EW-7438RPn webs formWlSiteSurvey stack-based overflowEPSS 0.8%CVE-2026-9344HIGHEdimax EW-7438RPn webs formWpsStart stack-based overflowEPSS 0.8%CVE-2026-9481HIGHEdimax EW-7438RPn formStats stack-based overflowEPSS 0.8%CVE-2026-9479HIGHEdimax EW-7438RPn formLogout stack-based overflowEPSS 0.8%CVE-2020-10639—Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A EPSS 0.8%CVE-2026-8234HIGHEFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflowEPSS 0.8%CVE-2026-18897HIGHUTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflowEPSS 0.8%CVE-2026-18895HIGHUTT HiPER 1250GW APSecurity_5g strcpy stack-based overflowEPSS 0.8%CVE-2024-12803HIGHA post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potenEPSS 0.8%CVE-2026-13564HIGHEdimax EW-7478APC POST Request formPPPoESetup stack-based overflowEPSS 0.8%CVE-2026-18898HIGHUTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflowEPSS 0.8%CVE-2024-5242HIGHTP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-39280—SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewEPSS 0.8%