Fallos del tipo CWE-121

3851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2025-9175MEDIUMneurobin shc shc.c make stack-based overflowEPSS 0.2%CVE-2026-26951MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.2%CVE-2020-37127MEDIUMdnsmasq-utils 2.79-1 - 'dhcp_release' Denial of ServiceEPSS 0.2%CVE-2026-40489HIGHeditorconfig-core-c has incomplete fix for CVE-2023-0341EPSS 0.2%CVE-2025-3916MEDIUMCWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentiallyEPSS 0.2%CVE-2023-25602HIGHA stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earliEPSS 0.2%CVE-2026-42805HIGHA stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser functEPSS 0.2%CVE-2025-40843MEDIUMBuffer overflow in CodeChecker log commandEPSS 0.2%CVE-2024-41902HIGHA vulnerability has been identified in JT2Go (All versions < V2406.0003). The affected application contains a stack-based buffer overflow vuEPSS 0.2%CVE-2024-39779MEDIUMStack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticateEPSS 0.2%CVE-2025-0649HIGHStack Exhaustion In Tensorflow ServingEPSS 0.2%CVE-2018-25360HIGHAgataSoft Auto PingMaster 1.5 Buffer Overflow SEHEPSS 0.2%CVE-2026-45250HIGHStack buffer overflow via setcred(2)EPSS 0.2%CVE-2023-46718MEDIUMA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 thrEPSS 0.2%CVE-2026-75676HIGHBridge | Stack-based Buffer Overflow (CWE-121)EPSS 0.2%CVE-2026-73070MEDIUMVim: Stack Buffer Overflow in the Vim Socket ServerEPSS 0.2%CVE-2026-28897MEDIUMA buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.EPSS 0.2%CVE-2026-36908MEDIUMA stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers tEPSS 0.2%CVE-2026-49033HIGHStack-Based Buffer Overflow in Labcenter ProteusEPSS 0.2%CVE-2025-24328MEDIUMOAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management networkEPSS 0.2%