Fallos del tipo CWE-121

3847 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-51383LOWD-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.EPSS 0.4%CVE-2025-60557HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.EPSS 0.4%CVE-2025-1364MEDIUMMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflowEPSS 0.4%CVE-2025-4480MEDIUMcode-projects Simple College Management System Add New Student input stack-based overflowEPSS 0.4%CVE-2026-81533MEDIUMMongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT ValuesEPSS 0.4%CVE-2026-22321MEDIUMStack-Based Buffer Overflow in CLI Login Username Handling over CLIEPSS 0.4%CVE-2023-5944HIGHDelta Electronics DOPSoft Stack-based Buffer OverflowEPSS 0.4%CVE-2024-39389HIGHAdobe Indesign PDF File Parsing Stack Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-45463HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-23339LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getEPSS 0.4%CVE-2026-50501HIGHWindows Resilient File System (ReFS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11578HIGHLuxion KeyShot 3DS File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-53593LOWQTS, QuTS heroEPSS 0.4%CVE-2025-70645HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This EPSS 0.4%CVE-2025-70656HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows EPSS 0.4%CVE-2025-71019HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. This vulnerability alEPSS 0.4%CVE-2025-70651HIGHTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulEPSS 0.4%CVE-2025-70644HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allowsEPSS 0.4%CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2025-70646HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allEPSS 0.4%