Fallos del tipo CWE-121

3833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-42942MEDIUMTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerabiliEPSS 0.7%CVE-2024-42945MEDIUMTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerabEPSS 0.7%CVE-2025-54482CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%CVE-2024-33782HIGHMP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. TEPSS 0.7%CVE-2025-45844HIGHTOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicEPSS 0.7%CVE-2025-45845HIGHTOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasEPSS 0.7%CVE-2024-28877HIGHMicroDicom DICOM Viewer Stack-based Buffer OverflowEPSS 0.7%CVE-2025-45843HIGHTOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestEPSS 0.7%CVE-2024-42940MEDIUMTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulneEPSS 0.7%CVE-2026-22903CRITICALStack Overflow via SESSIONID Cookie in lighttpdEPSS 0.7%CVE-2025-62691CRITICALSecurity Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HTTP headers. ReceivinEPSS 0.7%CVE-2026-30897MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7EPSS 0.7%CVE-2026-90823CRITICALFatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /uEPSS 0.7%CVE-2021-44158HIGHASUS RT-AX56U Router - Stack-based buffer overflowEPSS 0.7%CVE-2024-34202MEDIUMTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.EPSS 0.7%CVE-2026-76861HIGHNetcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_start_set.cgiEPSS 0.7%CVE-2025-24075HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-32291HIGHTenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.EPSS 0.7%CVE-2025-25457HIGHTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.EPSS 0.7%CVE-2025-61128CRITICALStack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other wavlink models alloEPSS 0.7%