Fallos del tipo CWE-121

3847 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-62852LOWQTS, QuTS heroEPSS 0.4%CVE-2025-70650HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg function. This vulnEPSS 0.4%CVE-2025-70645HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This EPSS 0.4%CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2025-53593LOWQTS, QuTS heroEPSS 0.4%CVE-2025-71020HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability alEPSS 0.4%CVE-2026-34122HIGHStack-based Buffer Overflow Leading to Denial of Service in TP-Link Tapo C520WSEPSS 0.4%CVE-2025-6663HIGHGStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-35333HIGHA stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper EPSS 0.4%CVE-2020-37142HIGH10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)EPSS 0.4%CVE-2024-41852HIGHAdobe Indesign 2024 AVI File Parsing Stack Based Buffer OverflowEPSS 0.4%CVE-2026-24911HIGHStack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service.EPSS 0.4%CVE-2024-30273HIGHAdobe Illustrator 2024 PS file Parsing Stack based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-9216LOWInsufficient input validation vulnerability exists in certain NETGEAR RAX ModelsEPSS 0.4%CVE-2024-36600HIGHBuffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image fiEPSS 0.4%CVE-2026-49789HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-41681HIGHrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkEPSS 0.4%CVE-2023-7339MEDIUMData collection for dowloading leads into buffer overflowEPSS 0.4%CVE-2020-37200MEDIUMNetShareWatcher 1.5.8.0 - 'Key' Denial of ServiceEPSS 0.4%CVE-2026-17259MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.4%