Fallos del tipo CWE-121

3837 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-67822CRITICALTenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDseEPSS 0.5%CVE-2026-8362CRITICALGladinet Triofox Stack-based Buffer Overflow in WOSDefaultHttpModule.dllEPSS 0.5%CVE-2026-91843CRITICALStack overflow in login process to the Security Management and Log ServersEPSS 0.5%CVE-2024-36468LOWStack buffer overflow in zbx_snmp_cache_handle_engineidEPSS 0.5%CVE-2024-28447MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cEPSS 0.5%CVE-2024-30585MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.EPSS 0.5%CVE-2025-60688MEDIUMA stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router fEPSS 0.5%CVE-2025-50662HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endEPSS 0.5%CVE-2025-60684MEDIUMA stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router fEPSS 0.5%CVE-2025-50663HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endEPSS 0.5%CVE-2024-30586MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.EPSS 0.5%CVE-2025-50660HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp enEPSS 0.5%CVE-2025-50655HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endEPSS 0.5%CVE-2025-50657HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpointEPSS 0.5%CVE-2025-50659HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp EPSS 0.5%CVE-2026-26239MEDIUMFile Station 5EPSS 0.5%CVE-2020-37133MEDIUMUltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of ServiceEPSS 0.5%CVE-2024-23982HIGHBIG-IP PEM vulnerabilityEPSS 0.5%CVE-2026-36778MEDIUMShenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameEPSS 0.5%CVE-2026-11733LOWBuffer overflow vulnerability in some NETGEAR Nighthawk routersEPSS 0.5%