Fallos del tipo CWE-121

3825 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2023-32149HIGHD-Link DIR-2640 prog.cgi Request Handling Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-23399HIGHA stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14.EPSS 1.2%CVE-2024-11061HIGHTenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflowEPSS 1.2%CVE-2025-6368HIGHD-Link DIR-619L formSetEmail stack-based overflowEPSS 1.2%CVE-2025-6370HIGHD-Link DIR-619L formWlanGuestSetup stack-based overflowEPSS 1.2%CVE-2025-6614HIGHD-Link DIR-619L formSetWANType_Wizard5 stack-based overflowEPSS 1.2%CVE-2025-6615HIGHD-Link DIR-619L formAutoDetecWAN_wizard4 stack-based overflowEPSS 1.2%CVE-2025-6511HIGHNetgear EX6150 sub_410090 stack-based overflowEPSS 1.2%CVE-2025-5798HIGHTenda AC8 SetSysTimeCfg fromSetSysTime stack-based overflowEPSS 1.2%CVE-2025-5799HIGHTenda AC8 WifiExtraSet fromSetWirelessRepeat stack-based overflowEPSS 1.2%CVE-2020-25857—The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) EPSS 1.2%CVE-2025-5600CRITICALTOTOLINK EX1200T cstecgi.cgi setLanguageCfg stack-based overflowEPSS 1.2%CVE-2023-24347HIGHD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcppluEPSS 1.2%CVE-2023-39435HIGHZavio IP Camera Stack-Based Buffer OverflowEPSS 1.2%CVE-2026-33250HIGHCrash when receiving specially-crafted packetsEPSS 1.2%CVE-2025-27481HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-1329HIGHTenda AX1803 WifiGuestSet fromGetWifiGuestBasic stack-based overflowEPSS 1.2%CVE-2024-27655HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers toEPSS 1.2%CVE-2024-8227HIGHTenda O1 DhcpSetSer fromDhcpSetSer stack-based overflowEPSS 1.2%CVE-2024-8225HIGHTenda G3 SetSysTimeCfg formSetSysTime stack-based overflowEPSS 1.2%