Weaknesses of type CWE-121

3,831 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-16096HIGHShibby Tomato webmon_recent_domains sub_40BB50 stack-based overflowEPSS 0.8%CVE-2026-6200HIGHTenda F456 webtypelibrary formwebtypelibrary stack-based overflowEPSS 0.8%CVE-2026-4490HIGHTenda A18 Pro openSchedWifi setSchedWifi stack-based overflowEPSS 0.8%CVE-2026-6194HIGHTotolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflowEPSS 0.8%CVE-2026-78169CRITICALUTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflowEPSS 0.8%CVE-2026-77148CRITICALComfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflowEPSS 0.8%CVE-2026-4492HIGHTenda A18 Pro formSetQosBand set_qosMib_list stack-based overflowEPSS 0.8%CVE-2025-15177HIGHTenda WH450 HTTP Request SetIpBind stack-based overflowEPSS 0.8%CVE-2025-15178HIGHTenda WH450 HTTP Request VirtualSer stack-based overflowEPSS 0.8%CVE-2025-45790MEDIUMTOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewEPSS 0.8%CVE-2025-45789MEDIUMTOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.EPSS 0.8%CVE-2025-45788MEDIUMTOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.EPSS 0.8%CVE-2023-54330CRITICALInbit Messenger 4.9.0 - Unauthenticated Remote SEH OverflowEPSS 0.8%CVE-2025-45787MEDIUMTOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.EPSS 0.8%CVE-2025-15163HIGHTenda WH450 SafeEmailFilter stack-based overflowEPSS 0.8%CVE-2025-15164HIGHTenda WH450 SafeMacFilter stack-based overflowEPSS 0.8%CVE-2025-15162HIGHTenda WH450 RouteStatic stack-based overflowEPSS 0.8%CVE-2024-32299HIGHTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.EPSS 0.8%CVE-2024-26010MEDIUMA stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FoEPSS 0.8%CVE-2025-15190HIGHD-Link DWR-M920 formFilter sub_42261C stack-based overflowEPSS 0.8%