Fallos del tipo CWE-121

3833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-41687CRITICALWeidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management APIEPSS 0.7%CVE-2026-2192HIGHTenda AC9 formGetRebootTimer stack-based overflowEPSS 0.7%CVE-2026-42468HIGHBuffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's phdr.len field is noEPSS 0.7%CVE-2026-2191HIGHTenda AC9 formGetDdosDefenceList stack-based overflowEPSS 0.7%CVE-2024-13903MEDIUMquickjs-ng QuickJS qjs quickjs.c JS_GetRuntime stack-based overflowEPSS 0.7%CVE-2024-30599HIGHTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.EPSS 0.7%CVE-2024-33215CRITICALTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goEPSS 0.7%CVE-2023-45984HIGHTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang paEPSS 0.7%CVE-2026-55687HIGHESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker ParsingEPSS 0.7%CVE-2023-23781MEDIUMA stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML sEPSS 0.7%CVE-2025-70234HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.EPSS 0.7%CVE-2024-30601HIGHTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.EPSS 0.7%CVE-2024-30583HIGHTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.EPSS 0.7%CVE-2024-47939HIGHStack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerEPSS 0.7%CVE-2024-32310HIGHTenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.EPSS 0.7%CVE-2024-30626HIGHTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.EPSS 0.7%CVE-2025-40795CRITICALA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All vEPSS 0.7%CVE-2024-30600HIGHTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.EPSS 0.7%CVE-2024-30625HIGHTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.EPSS 0.7%CVE-2024-30634HIGHTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.EPSS 0.7%