Fallos del tipo CWE-121

3851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-58303MEDIUMStack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30bEPSS 0.2%CVE-2025-40741HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based oEPSS 0.2%CVE-2026-36907MEDIUMA stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of EPSS 0.2%CVE-2023-44177MEDIUMJunos OS and Junos OS Evolved: Stack overflow vulnerability in CLI command processingEPSS 0.2%CVE-2026-39457HIGHStack overflow via select() file descriptor set overflowEPSS 0.2%CVE-2026-39461HIGHselect(2) file descriptor set overflow causes stack overflowEPSS 0.2%CVE-2026-10535HIGHIBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shellEPSS 0.2%CVE-2018-25344HIGH10-Strike Network Inventory Explorer 8.54 Buffer Overflow SEHEPSS 0.2%CVE-2025-58319HIGHFile Parsing Memory Corruption in CNCSoft-G2EPSS 0.2%CVE-2025-40580MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to aEPSS 0.2%CVE-2025-40579MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to aEPSS 0.2%CVE-2025-55116CRITICALBMC Control-M/Agent buffer overflow local privilege escalationEPSS 0.2%CVE-2023-20577HIGHA heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resEPSS 0.2%CVE-2024-38443MEDIUMC/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect commonEPSS 0.2%CVE-2026-6537MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-55728LOWLoytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflictEPSS 0.2%CVE-2026-6538MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2025-66215LOWOpenSC: Stack-buffer-overflow WRITE in card-oberthurEPSS 0.2%CVE-2018-25303HIGHAllok Video to DVD Burner 2.6.1217 Buffer Overflow SEHEPSS 0.2%CVE-2026-86140HIGHIn libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.EPSS 0.2%