Fallos del tipo CWE-121

3848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-32195HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-43520HIGHStack-based Buffer Overflow in WLAN HOSTEPSS 0.3%CVE-2023-51745HIGHA vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), TeamcenEPSS 0.3%CVE-2024-55577HIGHStack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file which is specially craEPSS 0.3%CVE-2025-7032HIGHRockwell Automation Stack-based Buffer Overflow In Arena® SimulationEPSS 0.3%CVE-2023-1709HIGHDatalogics Library APDFL Stack-based Buffer OverflowEPSS 0.3%CVE-2025-20719HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2022-43295MEDIUMXPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.EPSS 0.3%CVE-2026-16461MEDIUMRpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formattingEPSS 0.3%CVE-2023-37296HIGHStack-based Buffer OverflowEPSS 0.3%CVE-2019-25332HIGHFTP Commander Pro 8.03 - Local Stack OverflowEPSS 0.3%CVE-2025-21128HIGHSubstance3D - Stager | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-32708HIGHZenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)EPSS 0.3%CVE-2026-7192CRITICALMultiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network EquipmentEPSS 0.3%CVE-2026-18167HIGHStack-based buffer overflow in TP-Link Archer AX55 v4EPSS 0.3%CVE-2025-55660MEDIUMA stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of SeEPSS 0.3%CVE-2025-44900MEDIUMIn Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the pEPSS 0.3%CVE-2026-42804HIGHA stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commitEPSS 0.3%CVE-2026-40510LOWOpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.cEPSS 0.3%CVE-2023-48906MEDIUMStack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibbEPSS 0.3%