Fallos del tipo CWE-121

3834 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-53597LOWLicense CenterEPSS 0.6%CVE-2026-58179CRITICALApache Traffic Server: regex_remap plugin overflows the stack from attacker inputEPSS 0.6%CVE-2025-70245HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.EPSS 0.6%CVE-2024-46046MEDIUMTenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.EPSS 0.6%CVE-2024-25748HIGHA Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to exeEPSS 0.6%CVE-2023-35355HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-45846HIGHALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSettinEPSS 0.6%CVE-2020-36967HIGHZortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)EPSS 0.6%CVE-2025-23388HIGHUnauthenticated stack overflow in /v3-public/authproviders APIEPSS 0.6%CVE-2024-27567MEDIUMLBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vuEPSS 0.6%CVE-2024-52275HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.6%CVE-2024-41492HIGHA stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.6%CVE-2025-60334HIGHTOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. EPSS 0.6%CVE-2023-36729HIGHNamed Pipe File System Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-32307HIGHTenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.EPSS 0.6%CVE-2025-2151MEDIUMOpen Asset Import Library Assimp File ParsingUtils.h GetNextLine stack-based overflowEPSS 0.6%CVE-2025-70241HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.EPSS 0.6%CVE-2025-70236MEDIUMStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.EPSS 0.6%CVE-2026-2930MEDIUMTenda A18 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflowEPSS 0.6%CVE-2019-0053HIGHJunos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflowEPSS 0.6%