Fallos del tipo CWE-121

3840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-24882HIGHIn GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and EEPSS 0.4%CVE-2026-6665HIGHPgBouncer buffer overflow in SCRAMEPSS 0.4%CVE-2023-5407MEDIUMController denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security NotEPSS 0.4%CVE-2026-33447LOWCVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a EPSS 0.4%CVE-2024-35403LOWTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRuleEPSS 0.4%CVE-2017-12188—arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entrieEPSS 0.4%CVE-2026-13086CRITICALFireware OS Stack-Based Buffer Overflow in Mobile Security epm EndpointEPSS 0.4%CVE-2023-6749HIGHUnchecked user input length in the Zephyr Settings ShellEPSS 0.4%CVE-2026-88279MEDIUMGV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88280MEDIUMGV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88284MEDIUMGV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2026-88281MEDIUMGV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of ServiceEPSS 0.4%CVE-2026-88283MEDIUMGV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of ServiceEPSS 0.4%CVE-2025-44899CRITICALThere is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGEPSS 0.4%CVE-2023-50268MEDIUMjq has stack-based buffer overflow in decNaNsEPSS 0.4%CVE-2019-25340MEDIUMSpotAuditor 5.3.2 - 'Base64' Denial Of ServiceEPSS 0.4%CVE-2025-33202MEDIUMNVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack overflow by sending extrEPSS 0.4%CVE-2026-35717MEDIUMA stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attEPSS 0.4%CVE-2026-73783MEDIUMAuthenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CXEPSS 0.4%CVE-2026-10067HIGHShibby Tomato multimon.cgi sub_90F0 stack-based overflowEPSS 0.4%