Weaknesses of type CWE-121

3,831 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2026-94184HIGHFetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)EPSS 0.8%CVE-2024-32318CRITICALTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.EPSS 0.8%CVE-2025-60693MEDIUMA stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.0EPSS 0.8%CVE-2023-34426CRITICALA stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially craftEPSS 0.8%CVE-2023-34365CRITICALA stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially EPSS 0.8%CVE-2025-52999HIGHjackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested dataEPSS 0.8%CVE-2024-6744CRITICALThe SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability.EPSS 0.8%CVE-2020-27001—A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected appliEPSS 0.8%CVE-2026-69762HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-69503HIGHWindows USB Driver Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-54808CRITICALNetgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due tEPSS 0.8%CVE-2026-68834HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-69301HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-68838HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-69689HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-68878HIGHWindows Fast FAT Driver Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-69714HIGHWindows Device Association Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-8958HIGHTenda TX3 fast_setting_wifi_set stack-based overflowEPSS 0.8%CVE-2025-54402HIGHMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crEPSS 0.8%CVE-2025-54399HIGHMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crEPSS 0.8%