Fallos del tipo CWE-121

3841 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2023-46272HIGHBuffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute EPSS 0.4%CVE-2025-32061HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2012-10043CRITICALActFax 4.32 Client Importer Buffer OverflowEPSS 0.4%CVE-2025-60663HIGHTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.EPSS 0.4%CVE-2025-60341HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnEPSS 0.4%CVE-2025-55498HIGHTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.EPSS 0.4%CVE-2025-55852HIGHTenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.EPSS 0.4%CVE-2025-57086HIGHTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vuEPSS 0.4%CVE-2025-55564HIGHTenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.EPSS 0.4%CVE-2025-55483HIGHTenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and devicEPSS 0.4%CVE-2025-55482HIGHTenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.EPSS 0.4%CVE-2025-57078HIGHTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiEPSS 0.4%CVE-2024-23125HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2023-22226HIGHAdobe Bridge SVG file Stack-based Buffer Overflow Arbitrary code execution EPSS 0.4%CVE-2023-22234HIGHAdobe Premiere Rush PSD file Stack-based Buffer Overflow Arbitrary code execution EPSS 0.4%CVE-2023-22243HIGHAdobe Animate SVG file Stack-based Buffer Overflow Arbitrary code executionEPSS 0.4%CVE-2022-20824HIGHCisco FXOS and NX-OS Software Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2026-22213LOWRIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 UtilityEPSS 0.4%CVE-2025-28026HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 werEPSS 0.4%CVE-2025-28027HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 wasEPSS 0.4%