Fallos del tipo CWE-121

3836 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-30814HIGHBuffer Overflow Vulnerability in TP-Link AX53EPSS 0.6%CVE-2024-25176CRITICALLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.EPSS 0.6%CVE-2025-60674MEDIUMA stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling moEPSS 0.6%CVE-2022-1355—A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file toEPSS 0.6%CVE-2024-34020MEDIUMA stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.EPSS 0.6%CVE-2026-51843CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.EPSS 0.6%CVE-2026-51844CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.EPSS 0.6%CVE-2025-29214HIGHTenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.EPSS 0.6%CVE-2026-51845CRITICALTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.EPSS 0.6%CVE-2025-37169HIGHStack Overflow Vulnerability in AOS-10 Web-Based Management InterfaceEPSS 0.6%CVE-2024-34215HIGHTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.EPSS 0.6%CVE-2025-22900CRITICALTotolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig functionEPSS 0.6%CVE-2024-34201HIGHTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.EPSS 0.6%CVE-2024-34212HIGHTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.EPSS 0.6%CVE-2026-55738HIGHStack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name fieldEPSS 0.6%CVE-2024-42953MEDIUMTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulneraEPSS 0.6%CVE-2026-36822HIGHShenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelEPSS 0.6%CVE-2026-36793HIGHShenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the formwrlEPSS 0.6%CVE-2026-36819HIGHShenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the froEPSS 0.6%CVE-2026-36813HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the foEPSS 0.6%