Fallos del tipo CWE-121

3847 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-12186MEDIUMcode-projects Hotel Management System Available Room hotelnew.c stack-based overflowEPSS 0.3%CVE-2026-41286HIGHStack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant BEPSS 0.3%CVE-2010-20114HIGHVariCAD EN <= 2010-2.05 .dwb File Stack Buffer OverflowEPSS 0.3%CVE-2010-20123HIGHSteinberg MyMP3Player <= 3.0.0.67 Buffer OverflowEPSS 0.3%CVE-2010-20042HIGHXion Audio Player ≤ 1.0.126 Unicode Stack Buffer OverflowEPSS 0.3%CVE-2025-61498HIGHA buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying aEPSS 0.3%CVE-2009-20004HIGHgAlan <= 0.2.1 Buffer OverflowEPSS 0.3%CVE-2011-10021HIGHMagix Musik Maker <= v16 .mmm Stack-Based Buffer OverflowEPSS 0.3%CVE-2024-37003HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2026-5654MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2026-13309MEDIUMAutel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2017-7936—A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DuEPSS 0.3%CVE-2024-40412MEDIUMTenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.EPSS 0.3%CVE-2010-20045HIGHFileWrangler <= 5.30 Stack Buffer OverflowEPSS 0.3%CVE-2026-3081HIGHGStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-38752LOWA stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.3%CVE-2025-29118MEDIUMTenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.EPSS 0.3%CVE-2026-24497HIGHStack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: fromEPSS 0.3%CVE-2010-20010HIGHFoxit PDF Reader < 4.2.0.0928 Title Stack Buffer OverflowEPSS 0.3%CVE-2025-1366MEDIUMMicroWord eScan Antivirus VirusPopUp strcpy stack-based overflowEPSS 0.3%