Fallos del tipo CWE-121

3839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-5931MEDIUMBT: Unchecked user input in bap_broadcast_assistantEPSS 0.4%CVE-2023-34552MEDIUMIn certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP mEPSS 0.4%CVE-2026-10125HIGHEdimax BR-6478AC POST Request formPPPoESetup stack-based overflowEPSS 0.4%CVE-2026-10121HIGHTRENDnet TEW-432BRP formSetUrlFilter stack-based overflowEPSS 0.4%CVE-2025-69720HIGHThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.EPSS 0.4%CVE-2025-53022HIGHTrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmwarEPSS 0.4%CVE-2024-30631MEDIUMTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.EPSS 0.4%CVE-2025-70753HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function. This vulnerabilityEPSS 0.4%CVE-2025-71024HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. ThiEPSS 0.4%CVE-2024-30638MEDIUMTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.EPSS 0.4%CVE-2025-71025HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This EPSS 0.4%CVE-2025-71023HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerEPSS 0.4%CVE-2024-30588MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.EPSS 0.4%CVE-2025-71027HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulEPSS 0.4%CVE-2019-25329MEDIUMFTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)EPSS 0.4%CVE-2025-71026HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vEPSS 0.4%CVE-2026-86093HIGHIBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditionsEPSS 0.4%CVE-2026-101038CRITICALFAST FAC1200R MmtAtePrase stack-based overflowEPSS 0.4%CVE-2025-62858MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2026-24882HIGHIn GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and EEPSS 0.4%