Fallos del tipo CWE-121

3840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-56139MEDIUMA stack overflow Segmentation Fault (SEGV) and Memory Leak in pdftoolsEPSS 0.4%CVE-2024-52924HIGHAn issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 128EPSS 0.4%CVE-2025-59362MEDIUMSquid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.EPSS 0.4%CVE-2025-6073HIGHStack Buffer Overflow in MQTTCoreEPSS 0.4%CVE-2026-1425MEDIUMpymumu SmartDNS SVBC Record dns.c _dns_decode_SVCB_HTTPS stack-based overflowEPSS 0.4%CVE-2026-37536HIGHmiaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-EPSS 0.4%CVE-2026-86358MEDIUMDell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attackerEPSS 0.4%CVE-2024-49543HIGHInDesign Desktop | Stack-based Buffer Overflow (CWE-121)EPSS 0.4%CVE-2026-21903HIGHJunos OS: Subscribing to telemetry sensors at scale causes all FPCs to crashEPSS 0.4%CVE-2026-85506CRITICALipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-EPSS 0.4%CVE-2026-85504CRITICALFreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-stringEPSS 0.4%CVE-2026-85508CRITICALipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (EPSS 0.4%CVE-2026-85507CRITICALipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-iEPSS 0.4%CVE-2026-85509CRITICALFreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than EPSS 0.4%CVE-2021-3790MEDIUMA buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated EPSS 0.4%CVE-2024-5305HIGHKofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-34287HIGHAshlar-Vellum Cobalt CO File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-27821HIGHGPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer OverflowEPSS 0.4%CVE-2025-53418HIGHCOMMGR Stack-based Buffer Overflow VulnerabilityEPSS 0.4%CVE-2026-33449LOWMessage handler buffer overflow in clients prior to 14.50EPSS 0.4%