Fallos del tipo CWE-121

3839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-10161HIGHTRENDnet TEW-432BRP formResetStatistic stack-based overflowEPSS 0.5%CVE-2026-10119HIGHTRENDnet TEW-432BRP formSetMACFilter stack-based overflowEPSS 0.5%CVE-2026-10162HIGHTRENDnet TEW-432BRP formSetPassword stack-based overflowEPSS 0.5%CVE-2022-3159HIGHThe APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This EPSS 0.5%CVE-2026-10293HIGHUTT HiPER 1200GW formFireWall strcpy stack-based overflowEPSS 0.5%CVE-2026-10122HIGHTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowEPSS 0.5%CVE-2026-10124HIGHShibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflowEPSS 0.5%CVE-2026-40130MEDIUMMemory Corruption vulnerability in SAPSPrint ServiceEPSS 0.5%CVE-2026-10160HIGHTRENDnet TEW-432BRP formSetEnableWizard stack-based overflowEPSS 0.5%CVE-2026-10183HIGHTRENDnet TEW-432BRP formWlanSetup stack-based overflowEPSS 0.5%CVE-2026-10123HIGHTRENDnet TEW-432BRP formSetDomainFilter stack-based overflowEPSS 0.5%CVE-2026-10292HIGHUTT HiPER 1200GW formTaskEdit strcpy stack-based overflowEPSS 0.5%CVE-2026-10181HIGHTRENDnet TEW-432BRP formSysCmd stack-based overflowEPSS 0.5%CVE-2026-10165HIGHEdimax BR-6478AC POST Request formWanTcpipSetup stack-based overflowEPSS 0.5%CVE-2026-10829HIGHA stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerabiliEPSS 0.5%CVE-2026-19318CRITICALFireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code ExecutionEPSS 0.5%CVE-2024-23138HIGHStack-based Overflow Vulnerability in the TrueViewTM Desktop SoftwareEPSS 0.5%CVE-2026-43798CRITICALA single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and contenEPSS 0.5%CVE-2019-25319HIGHDomain Quester Pro 6.02 - Stack Overflow (SEH)EPSS 0.5%CVE-2019-25365HIGHChaosPro 2.0 - Buffer OverflowEPSS 0.5%