Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2021-21573HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%CVE-2023-46720MEDIUMA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 thrEPSS 0.3%CVE-2025-8962MEDIUMcode-projects Hostel Management System Login Form hostel_manage.exe stack-based overflowEPSS 0.3%CVE-2025-8845MEDIUMNASM Netwide Assember nasm.c assemble_file stack-based overflowEPSS 0.3%CVE-2025-8846MEDIUMNASM Netwide Assember parser.c parse_line stack-based overflowEPSS 0.3%CVE-2025-20794MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.3%CVE-2026-6240MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WSEPSS 0.3%CVE-2025-55503HIGHTenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.EPSS 0.3%CVE-2026-6239MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WSEPSS 0.3%CVE-2025-30298HIGHAdobe Framemaker | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2025-27168HIGHIllustrator | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-2016MEDIUMhappyfish100 libfastcommon base64.c base64_decode stack-based overflowEPSS 0.3%CVE-2024-9745HIGHTungsten Automation Power PDF TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-5295MEDIUMStack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OIDEPSS 0.3%CVE-2025-46398MEDIUMXfig: fig2dev stack-overflow via read_objectsEPSS 0.3%CVE-2024-39480HIGHkdb: Fix buffer overflow during tab-completeEPSS 0.3%CVE-2025-25679HIGHTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.EPSS 0.3%CVE-2022-1888HIGHFuji Electric Alpha7 PC Loader Fuji Electric Alpha7 PC LoaderEPSS 0.3%CVE-2024-1151MEDIUMKernel: stack overflow problem in open vswitch kernel module leading to dosEPSS 0.3%CVE-2024-53311MEDIUMA Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via aEPSS 0.3%