Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-71337HIGHWindows Storage Management Provider Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-66877HIGHBuffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.EPSS 0.3%CVE-2026-62755HIGHWindows DHCP Client Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-40399HIGHWindows TCP/IP Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50400HIGHWindows App Package Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50387HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2019-25435HIGHSricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP BypassEPSS 0.3%CVE-2026-50412HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70344HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70346HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69467HIGHMicrosoft Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62877HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-83990HIGHMicrosoft Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62768HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69290HIGHWindows Storage Spaces Controller Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50318HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-10898HIGHStack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2022-40201HIGHBentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed desigEPSS 0.3%CVE-2025-25740MEDIUMD-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSeEPSS 0.3%CVE-2026-6791MEDIUMPotential stack-based buffer clash during tilde expansion in wordexpEPSS 0.3%