Fallos del tipo CWE-121

3825 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-2927HIGHD-Link DWR-M960 Operation Mode Configuration Endpoint formOpMode sub_462590 stack-based overflowEPSS 1.2%CVE-2024-34087CRITICALAn SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve rEPSS 1.2%CVE-2025-55763HIGHBuffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a craEPSS 1.2%CVE-2024-31470CRITICALThere is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthentiEPSS 1.2%CVE-2024-2547HIGHTenda AC18 R7WebsSecurityHandler stack-based overflowEPSS 1.2%CVE-2012-10031HIGHBlazeVideo HDTV Player Pro 6.6.0.3 Filename Handling Buffer OverflowEPSS 1.2%CVE-2025-15194CRITICALD-Link DIR-600 HTTP Header hedwig.cgi stack-based overflowEPSS 1.2%CVE-2022-21228HIGHICSA-22-090-03 Fuji Electric Alpha5EPSS 1.2%CVE-2025-40601HIGHA Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of ServicEPSS 1.2%CVE-2025-6617HIGHD-Link DIR-619L formAdvanceSetup stack-based overflowEPSS 1.2%CVE-2025-6158HIGHD-Link DIR-665 HTTP POST Request sub_AC78 stack-based overflowEPSS 1.2%CVE-2021-30496MEDIUMThe Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an atEPSS 1.2%CVE-2023-54329CRITICALInbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE)EPSS 1.2%CVE-2025-15047CRITICALTenda WH450 HTTP Request PPTPDClient stack-based overflowEPSS 1.2%CVE-2026-50368HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%CVE-2026-50695HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%CVE-2026-50304HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%CVE-2026-50527HIGH.NET Framework Denial of Service VulnerabilityEPSS 1.2%CVE-2026-50355HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%CVE-2026-54983HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%