Fallos del tipo CWE-121

3851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-30983HIGHiccDEV has a stack buffer overflow in icFixXml()EPSS 0.2%CVE-2026-81433HIGHFireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code ExecutionEPSS 0.2%CVE-2026-30987HIGHiccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()EPSS 0.2%CVE-2019-25334MEDIUMProduct Key Explorer 4.2.0.0 - 'Name' Denial of ServiceEPSS 0.2%CVE-2026-14606HIGHRT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflowEPSS 0.2%CVE-2026-73600HIGHDell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A hiEPSS 0.2%CVE-2026-14605HIGHRT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflowEPSS 0.2%CVE-2026-0660HIGHStack Based Buffer Overflow in GIF File ParsingEPSS 0.2%CVE-2025-6141MEDIUMGNU ncurses parse_entry.c postprocess_termcap stack-based overflowEPSS 0.2%CVE-2025-43374MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS SeqEPSS 0.2%CVE-2025-46836MEDIUMnet-tools Stack-based Buffer Overflow vulnerabilityEPSS 0.2%CVE-2022-26860HIGHDell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicioEPSS 0.2%CVE-2026-33491HIGHZen-C has Stack-Based Buffer Overflow in Identifier ManglingEPSS 0.2%CVE-2026-30363HIGHflipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.EPSS 0.2%CVE-2026-15166MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2022-32493MEDIUMDell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiEPSS 0.2%CVE-2023-23580MEDIUMStack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an EPSS 0.2%CVE-2026-54758HIGHNotepad++: Stack Buffer Overflow in expandNppEnvironmentStrsEPSS 0.2%CVE-2025-9175MEDIUMneurobin shc shc.c make stack-based overflowEPSS 0.2%CVE-2026-26951MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.2%