Fallos del tipo CWE-121

3839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-28030HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRulEPSS 0.5%CVE-2024-32306MEDIUMTenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.EPSS 0.5%CVE-2025-70250HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.EPSS 0.5%CVE-2026-101037CRITICALFAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflowEPSS 0.5%CVE-2025-26386HIGHStack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) toolEPSS 0.5%CVE-2026-22214MEDIUMRIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame ParserEPSS 0.5%CVE-2026-16418HIGHStack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.5%CVE-2026-78910HIGHBuffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a cEPSS 0.5%CVE-2026-57165MEDIUMPJSIP: Pre-authentication overflow in the telnet CLI historyEPSS 0.5%CVE-2024-3286HIGH A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restartEPSS 0.5%CVE-2025-70746HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime function. This vulnerabiliEPSS 0.5%CVE-2026-68516MEDIUMOpenEXR: HTJ2K SIZ image-offset gap stack buffer overflowEPSS 0.5%CVE-2024-52272HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2024-52273HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2025-34124HIGHHeroes of Might and Magic III .h3m Map File Buffer OverflowEPSS 0.4%CVE-2024-25137MEDIUMAutomationDirect C-MORE EA9 HMI Stack-based Buffer OverflowEPSS 0.4%CVE-2024-52274HIGHDenial of Service on Tenda AC6V2 Due To Stack OverflowEPSS 0.4%CVE-2026-93372CRITICALBuffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside tEPSS 0.4%CVE-2025-71021HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability EPSS 0.4%CVE-2023-34552MEDIUMIn certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP mEPSS 0.4%