Fallos del tipo CWE-121

3834 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-5245MEDIUMCesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflowEPSS 0.6%CVE-2026-27671CRITICALMemory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP PlatformEPSS 0.6%CVE-2024-44859HIGHTenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.EPSS 0.6%CVE-2023-4601HIGHStack-based Buffer Overflow in NI System Configuration SoftwareEPSS 0.6%CVE-2025-60331HIGHD-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This EPSS 0.6%CVE-2026-44859HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44858HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44857HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44856HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44855HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-81480HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged atEPSS 0.6%CVE-2026-0719HIGHLibsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationEPSS 0.6%CVE-2025-29100CRITICALTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.EPSS 0.6%CVE-2024-33517MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. SucceEPSS 0.6%CVE-2024-46049MEDIUMTenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.EPSS 0.6%CVE-2024-33514MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.6%CVE-2024-33515MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.6%CVE-2024-31163HIGHASUS Download Master - Buffer OverflowEPSS 0.6%CVE-2024-33516MEDIUMAn unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. SucEPSS 0.6%CVE-2024-46044MEDIUMCH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.EPSS 0.6%