Fallos del tipo CWE-121

3831 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2010-10014HIGHOdin Secure FTP <= 4.1 Stack Buffer Overflow via LIST ResponseEPSS 1.0%CVE-2026-2871HIGHTenda A21 SetIpMacBind fromSetIpMacBind stack-based overflowEPSS 1.0%CVE-2025-12241HIGHTOTOLINK A3300R POST Parameter cstecgi.cgi setLanguageCfg stack-based overflowEPSS 1.0%CVE-2025-12225HIGHTenda AC6 HTTP Request WifiGuestSet stack-based overflowEPSS 1.0%CVE-2024-7439HIGHVivotek CC8160 httpd read stack-based overflowEPSS 1.0%CVE-2025-12209HIGHTenda O3 setDhcpConfig GetValue stack-based overflowEPSS 1.0%CVE-2025-11524HIGHTenda AC7 SetDDNSCfg stack-based overflowEPSS 1.0%CVE-2024-10123HIGHTenda AC8 saveParentControlInfo compare_parentcontrol_time stack-based overflowEPSS 1.0%CVE-2024-10130HIGHTenda AC8 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflowEPSS 1.0%CVE-2024-23934HIGHSony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-2909HIGHTenda HG9 Diagnostic Ping Endpoint formPing stack-based overflowEPSS 1.0%CVE-2026-2872HIGHTenda A21 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflowEPSS 1.0%CVE-2026-2907HIGHTenda HG9 GPON Configuration Endpoint formgponConf stack-based overflowEPSS 1.0%CVE-2026-2886HIGHTenda A21 SetOnlineDevName set_device_name stack-based overflowEPSS 1.0%CVE-2026-2873HIGHTenda A21 openSchedWifi setSchedWifi stack-based overflowEPSS 1.0%CVE-2026-2910HIGHTenda HG9 formPing6 stack-based overflowEPSS 1.0%CVE-2026-2870HIGHTenda A21 formSetQosBand set_qosMib_list stack-based overflowEPSS 1.0%CVE-2018-14793—DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to alloEPSS 1.0%CVE-2026-2906HIGHTenda HG9 Samba Configuration Endpoint formSamba stack-based overflowEPSS 1.0%CVE-2026-2908HIGHTenda HG9 Loopback Detection Configuration Endpoint formLoopBack stack-based overflowEPSS 1.0%