Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-16832HIGHPower System Buffer OverflowEPSS 0.3%CVE-2018-7514—Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prEPSS 0.3%CVE-2025-59383LOWMedia Streaming Add-onEPSS 0.3%CVE-2025-4038MEDIUMcode-projects Train Ticket Reservation System reservation stack-based overflowEPSS 0.3%CVE-2026-88388HIGHEspruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-EPSS 0.3%CVE-2025-58413MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, EPSS 0.3%CVE-2025-8404MEDIUMStack buffer overflow vulnerability exists in the Supermicro BMC Shared libraryEPSS 0.3%CVE-2026-22320MEDIUMStack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIEPSS 0.3%CVE-2019-25341MEDIUMiNetTools for iOS 8.20 - 'Whois' Denial of ServiceEPSS 0.3%CVE-2026-31267MEDIUMMercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overfEPSS 0.3%CVE-2025-3196MEDIUMOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflowEPSS 0.3%CVE-2023-27590HIGHRizin has stack-based buffer overflow when parsing GDB registers profile filesEPSS 0.3%CVE-2026-21224HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2019-25434MEDIUMSpotAuditor 5.3.1.0 Denial of Service via Registration Name FieldEPSS 0.3%CVE-2025-49564HIGHIllustrator | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2024-23798HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2019-25062MEDIUMSricam IP CCTV Camera Device Viewer stack-based overflowEPSS 0.3%CVE-2024-51473MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2024-23797HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.3%CVE-2026-76879HIGHStack-based Buffer Overflow in WiresharkEPSS 0.3%