Fallos del tipo CWE-121

3840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-35716MEDIUMA stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attaEPSS 0.4%CVE-2025-26595HIGHXorg: xwayland: buffer overflow in xkbvmodmasktext()EPSS 0.4%CVE-2026-10066HIGHShibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflowEPSS 0.4%CVE-2026-10065HIGHShibby Tomato tomatodata.cgi get_ups_field stack-based overflowEPSS 0.4%CVE-2025-66280MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2021-31420HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.0-48950. An attacker muEPSS 0.4%CVE-2026-25727MEDIUMtime affected by a stack exhaustion denial of service attackEPSS 0.4%CVE-2023-35702HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2020-37184HIGHAllok Video Converter 4.6.1217 - Stack Overflow (SEH)EPSS 0.4%CVE-2020-37181MEDIUMTorrent FLV Converter 1.51 Build 117 - Stack Oveflow (SEH partial overwrite)EPSS 0.4%CVE-2026-25967HIGHImageMagick has stack buffer overflow in FTXT reader via oversized integer fieldEPSS 0.4%CVE-2023-35703HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2023-35704HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2020-37183HIGHAllok RM RMVB to AVI MPEG DVD Converter 3.6.1217 - Stack Overflow (SEH)EPSS 0.4%CVE-2020-37176HIGHTorrent 3GP Converter 1.51 - Stack Overflow (SEH)EPSS 0.4%CVE-2024-33211HIGHTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/gEPSS 0.4%CVE-2024-35399HIGHTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuthEPSS 0.4%CVE-2025-41730CRITICALStack-based buffer overflow via unsafe sscanf in check_account()EPSS 0.4%CVE-2026-43831HIGHtbcEPSS 0.4%CVE-2026-43829HIGHtbcEPSS 0.4%