Fallos del tipo CWE-121

3845 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-60559HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.EPSS 0.4%CVE-2025-6072HIGHStack Buffer Overflow in MQTTCoreEPSS 0.4%CVE-2020-37066HIGHGoldWave 5.70 – Buffer Overflow (SEH Unicode)EPSS 0.4%CVE-2025-60568HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.EPSS 0.4%CVE-2025-60563HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.EPSS 0.4%CVE-2025-60555HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.EPSS 0.4%CVE-2025-60556HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.EPSS 0.4%CVE-2025-60551HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.EPSS 0.4%CVE-2025-60552HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.EPSS 0.4%CVE-2025-60549HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.EPSS 0.4%CVE-2025-60547HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.EPSS 0.4%CVE-2025-60564HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.EPSS 0.4%CVE-2025-60562HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.EPSS 0.4%CVE-2025-60565HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.EPSS 0.4%CVE-2025-60550HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.EPSS 0.4%CVE-2025-4471MEDIUMcode-projects Jewelery Store Management system Search Item View stack-based overflowEPSS 0.4%CVE-2025-11784HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11782HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11785HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11786HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%