Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2021-21574HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%CVE-2024-28574MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the oEPSS 0.3%CVE-2024-41166MEDIUMStack-based buffer overflow in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an EPSS 0.3%CVE-2025-3007MEDIUMNovastar CX40 NetFilter Utility netconfig getopt stack-based overflowEPSS 0.3%CVE-2023-29583MEDIUMyasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been dispEPSS 0.3%CVE-2024-11790HIGHFuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-71265HIGHDomoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()EPSS 0.3%CVE-2025-11678HIGHStack-based Buffer Overflow in libwebsockets DNS response parsingEPSS 0.3%CVE-2025-43025MEDIUMHP Universal Print Driver – Potential Denial of ServiceEPSS 0.3%CVE-2024-28575HIGHBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the oEPSS 0.3%CVE-2024-7013HIGHStack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execute arbitrary code viaEPSS 0.3%CVE-2025-6857MEDIUMHDF5 H5Gnode.c H5G__node_cmp3 stack-based overflowEPSS 0.3%CVE-2023-28728HIGHA stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution wEPSS 0.3%CVE-2025-8477HIGHAlpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-11793MEDIUM389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id parsingEPSS 0.3%CVE-2024-23110HIGHA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.EPSS 0.3%CVE-2026-6868MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2026-32705MEDIUMPX4 autopilot BST Device Name Length Can Overflow Driver BufferEPSS 0.3%CVE-2023-46720MEDIUMA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 thrEPSS 0.3%CVE-2021-21573HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%