Fallos del tipo CWE-121

3840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-32317HIGHTenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSEPSS 0.4%CVE-2026-33554HIGHipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMEPSS 0.4%CVE-2024-33213MEDIUMTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goEPSS 0.4%CVE-2026-57163HIGHPJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backendEPSS 0.4%CVE-2024-32316MEDIUMTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.EPSS 0.4%CVE-2024-40417MEDIUMA vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBinEPSS 0.4%CVE-2012-10051HIGHPhotodex ProShow Producer 5.0.3256 load File Handling Buffer OverflowEPSS 0.4%CVE-2026-10064MEDIUMTRENDnet TEW-432BRP formSetPortTr stack-based overflowEPSS 0.4%CVE-2023-38094HIGHKofax Power PDF replacePages Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38092HIGHKofax Power PDF importDataObject Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-47410HIGHAnimate | Stack-based Buffer Overflow (CWE-121)EPSS 0.4%CVE-2023-38093HIGHKofax Power PDF saveAs Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-3729LOWRSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Buffer Overflow vulnerEPSS 0.4%CVE-2024-49350MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2025-32061HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2012-10043CRITICALActFax 4.32 Client Importer Buffer OverflowEPSS 0.4%CVE-2026-49943MEDIUMCZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation inEPSS 0.4%CVE-2023-40484HIGHMaxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-32062HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2023-40486HIGHMaxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%