Fallos del tipo CWE-121

3839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-81532HIGHBI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionEPSS 0.5%CVE-2009-20002HIGHMillenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer OverflowEPSS 0.5%CVE-2026-13361HIGHIBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code ExecutionEPSS 0.5%CVE-2025-57057HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulEPSS 0.5%CVE-2025-57064HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vEPSS 0.5%CVE-2025-57060HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vEPSS 0.5%CVE-2025-57062HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vEPSS 0.5%CVE-2025-57070HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulEPSS 0.5%CVE-2025-57072HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute functioEPSS 0.5%CVE-2025-57059HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerabEPSS 0.5%CVE-2025-57069HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnEPSS 0.5%CVE-2025-57063HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function.EPSS 0.5%CVE-2025-57058HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and EPSS 0.5%CVE-2025-57087HIGHTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. ThEPSS 0.5%CVE-2025-57061HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, EPSS 0.5%CVE-2025-4472MEDIUMcode-projects Departmental Store Management System bill stack-based overflowEPSS 0.5%CVE-2023-24334HIGHA stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary comEPSS 0.5%CVE-2025-2837HIGHSilicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-57071HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulneEPSS 0.5%CVE-2026-89020MEDIUMMikroTik RouterOS Stack Buffer Overflow via TFTP URL PathEPSS 0.5%