Fallos del tipo CWE-121

3833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2017-16332HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16310HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16275HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16335HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16308HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16278HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2026-51807CRITICALHeap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caEPSS 0.7%CVE-2024-37634CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.EPSS 0.7%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 0.7%CVE-2026-59837MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2,EPSS 0.7%CVE-2020-37138HIGH10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)EPSS 0.7%CVE-2024-30612HIGHTenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState funcEPSS 0.7%CVE-2025-60679HIGHA stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cEPSS 0.7%CVE-2025-40634CRITICALStack-based buffer overflow in TP-Link Archer AX50EPSS 0.7%CVE-2026-58181HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crashEPSS 0.7%CVE-2024-30394HIGHJunos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crashEPSS 0.7%CVE-2026-58180HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker inputEPSS 0.7%CVE-2025-14423HIGHGIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-37635CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfgEPSS 0.7%CVE-2026-67379HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.7%