Fallos del tipo CWE-121

3825 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-50411HIGHWindows Active Directory Federation Services Denial of Service VulnerabilityEPSS 1.2%CVE-2025-9089HIGHTenda AC20 SetIpMacBind sub_48E628 stack-based overflowEPSS 1.2%CVE-2025-6328HIGHD-Link DIR-815 hedwig.cgi sub_403794 stack-based overflowEPSS 1.2%CVE-2026-3978HIGHD-Link DIR-513 formEasySetupWizard3 stack-based overflowEPSS 1.2%CVE-2026-5213HIGHD-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflowEPSS 1.2%CVE-2026-5214HIGHD-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflowEPSS 1.2%CVE-2026-5211HIGHD-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflowEPSS 1.2%CVE-2026-4555HIGHD-Link DIR-513 boa formEasySetTimezone memory corruptionEPSS 1.2%CVE-2026-5024HIGHD-Link DIR-513 formSetEmail stack-based overflowEPSS 1.2%CVE-2024-10194HIGHWAVLINK WN530H4/WN530HG4/WN572HG3 Front-End Authentication Page login.cgi Goto_chidx stack-based overflowEPSS 1.2%CVE-2024-24963CRITICALA stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-55EPSS 1.2%CVE-2024-10661HIGHTenda AC15 SetDlnaCfg stack-based overflowEPSS 1.2%CVE-2023-0853CRITICALBuffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may alloEPSS 1.2%CVE-2026-5212HIGHD-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflowEPSS 1.2%CVE-2024-24962CRITICALA stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-55EPSS 1.2%CVE-2024-28899HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2024-2856HIGHTenda AC10 SetSysTimeCfg fromSetSysTime stack-based overflowEPSS 1.2%CVE-2025-4354HIGHTenda DAP-1520 storage check_dws_cookie stack-based overflowEPSS 1.2%CVE-2025-0848HIGHTenda A18 HTTP POST Request SetCmdlineRun stack-based overflowEPSS 1.2%CVE-2024-6962HIGHTenda O3 formQosSet stack-based overflowEPSS 1.2%