Fallos del tipo CWE-121

3839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-1163MEDIUMcode-projects Vehicle Parking Management System Authentication login stack-based overflowEPSS 0.5%CVE-2026-17138HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-68863HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with reEPSS 0.5%CVE-2023-0426HIGHStack overflow in filename or in boundary EPSS 0.5%CVE-2026-11553HIGHTenda HG7HG9/HG10 formPPPEdit stack-based overflowEPSS 0.5%CVE-2024-49537HIGHAfter Effects | Stack-based Buffer Overflow (CWE-121)EPSS 0.5%CVE-2026-10188HIGHTenda W12 httpd cgistaKickOff stack-based overflowEPSS 0.5%CVE-2026-11557HIGHTenda F451 Web Management Natlimit fromNatlimit stack-based overflowEPSS 0.5%CVE-2026-10191HIGHTenda W12 httpd cgiWifiMacFilterSet stack-based overflowEPSS 0.5%CVE-2024-20524MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Denial of Service VulnerabilitiesEPSS 0.5%CVE-2019-16470HIGHCoolType.dll crash - Tianfu CupEPSS 0.5%CVE-2024-20523MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Denial of Service VulnerabilitiesEPSS 0.5%CVE-2025-66176HIGHThere is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an aEPSS 0.5%CVE-2025-64096HIGHCryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length checkEPSS 0.5%CVE-2025-29101HIGHTenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info functionEPSS 0.5%CVE-2025-29121HIGHA vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file fEPSS 0.5%CVE-2025-29149HIGHTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.EPSS 0.5%CVE-2021-47789MEDIUMYenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)EPSS 0.5%CVE-2026-10292HIGHUTT HiPER 1200GW formTaskEdit strcpy stack-based overflowEPSS 0.5%CVE-2026-10181HIGHTRENDnet TEW-432BRP formSysCmd stack-based overflowEPSS 0.5%