Fallos del tipo CWE-121

3833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-60691HIGHA stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi aEPSS 0.7%CVE-2025-70237HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.EPSS 0.7%CVE-2025-54480CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%CVE-2025-66043CRITICALSeveral stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A speciaEPSS 0.7%CVE-2025-66048CRITICALSeveral stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A speciaEPSS 0.7%CVE-2026-1637HIGHTenda AC21 AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflowEPSS 0.7%CVE-2023-27346HIGHTP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2020-37095HIGHCyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)EPSS 0.7%CVE-2025-44893CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post fuEPSS 0.7%CVE-2014-125114HIGHi-Ftp 2.20 Schedule.xml Stack-Based Buffer OverflowEPSS 0.7%CVE-2026-81944HIGHPLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web ServerEPSS 0.7%CVE-2022-23460MEDIUMStack overflow in JsonxxEPSS 0.7%CVE-2023-7187MEDIUMTotolink N350RT HTTP POST Request stack-based overflowEPSS 0.7%CVE-2026-38422HIGHBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/taEPSS 0.7%CVE-2026-90688HIGHTenda W20E HTTP formIPMacBindAdd stack-based overflowEPSS 0.7%CVE-2026-69510HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-62792HIGHWindows TCP/IP Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-69620HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-54489CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%CVE-2025-54481CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%