Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-5297MEDIUMSourceCodester Computer Store System main.c Add stack-based overflowEPSS 0.3%CVE-2024-52894MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2025-49589MEDIUMPCSX2 Contains a Stack-based Buffer Overflow in IOP Console LoggingEPSS 0.3%CVE-2026-23747MEDIUMGolioth Firmware SDK < 0.22.0 Payload Utils Stack-based Buffer OverflowEPSS 0.3%CVE-2025-58317HIGHFile Parsing Memory Corruption in CNCSoft-G2EPSS 0.3%CVE-2025-25634MEDIUMA vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The EPSS 0.3%CVE-2019-25318HIGHAVS Audio Converter 9.1.2.600 - Stack OverflowEPSS 0.3%CVE-2024-39354HIGHDelta Electronics DIAScreen Stack-based Buffer OverflowEPSS 0.3%CVE-2019-16641HIGHAn issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.phEPSS 0.3%CVE-2024-30840MEDIUMA Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromEPSS 0.3%CVE-2024-49828MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2024-47131HIGHDelta Electronics DIAScreen Stack-based Buffer OverflowEPSS 0.3%CVE-2024-47135HIGHStack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6EPSS 0.3%CVE-2024-44390HIGHTenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.EPSS 0.3%CVE-2023-35127HIGHFuji Electric Tellus Lite V-Simulator Stack-based Buffer OverflowEPSS 0.3%CVE-2026-17250HIGHAuthenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update HandlingEPSS 0.3%CVE-2025-1533HIGHA stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading EPSS 0.3%CVE-2024-7539HIGHoFono CUSD Stack-based Buffer Overflow Code Execution VulnerabilityEPSS 0.3%CVE-2025-65223MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.EPSS 0.3%CVE-2025-65221MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.EPSS 0.3%