Fallos del tipo CWE-121

3849 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-39853HIGHosslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature VerificationEPSS 0.2%CVE-2023-21414HIGHNCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (EPSS 0.2%CVE-2026-32925HIGHV-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 filEPSS 0.2%CVE-2026-32928HIGHV-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 fEPSS 0.2%CVE-2023-51792LOWBuffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding theEPSS 0.2%CVE-2025-5555HIGHNixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflowEPSS 0.2%CVE-2025-7704MEDIUMSupermicro BMC SMASH services has a Stack-based buffer overflow vulnerabilityEPSS 0.2%CVE-2025-60696HIGHA stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012)EPSS 0.2%CVE-2025-60692HIGHA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001EPSS 0.2%CVE-2024-33577HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerabilEPSS 0.2%CVE-2023-4685HIGHCVE-2023-4685EPSS 0.2%CVE-2023-29503HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a sEPSS 0.2%CVE-2023-37374HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2023-37375HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2026-86054HIGHNotepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session pathEPSS 0.2%CVE-2023-45601HIGHA vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1.250), Parasolid V36EPSS 0.2%CVE-2024-31496MEDIUMA stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer vEPSS 0.2%CVE-2025-34450MEDIUMmerbanan/rtl_433 <= 25.02 Stack-based Buffer OverflowEPSS 0.2%CVE-2022-36337HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration drivEPSS 0.2%CVE-2022-47936HIGHA vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Parasolid V34.0 (All verEPSS 0.2%