Fallos del tipo CWE-121

3826 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2026-78439HIGHMicrosoft Office Graphics Component Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-37050MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2024-37047MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-12211HIGHTenda O3 setDmzInfo GetValue stack-based overflowEPSS 0.8%CVE-2020-1605HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.EPSS 0.8%CVE-2026-10062HIGHTRENDnet TEW-432BRP formSetRoute stack-based overflowEPSS 0.8%CVE-2026-39047HIGHBuffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirEPSS 0.8%CVE-2024-46435HIGHA stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a dEPSS 0.8%CVE-2025-7796HIGHTenda FH451 PPTPDClient fromPptpUserAdd stack-based overflowEPSS 0.8%CVE-2025-7434HIGHTenda FH451 POST Request addressNat fromAddressNat stack-based overflowEPSS 0.8%CVE-2023-40478HIGHNETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-15722HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsingEPSS 0.8%CVE-2026-42854CRITICALarduino-esp32: Stack buffer overflow in WebServer multipart boundary parsing leads to remote crash potential RCEEPSS 0.8%CVE-2024-58299CRITICALPCMan FTP Server 2.0 Remote Buffer Overflow via 'pwd' CommandEPSS 0.8%CVE-2025-11386HIGHTenda AC15 POST Parameter SetDDNSCfg stack-based overflowEPSS 0.8%CVE-2025-11324HIGHTenda AC18 setNotUpgrade stack-based overflowEPSS 0.8%CVE-2024-3079HIGHASUS Router - Stack-based Buffer OverflowEPSS 0.8%CVE-2025-7921CRITICALASKEY|modem - Stack-based Buffer OverflowEPSS 0.8%CVE-2025-29215MEDIUMTenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.EPSS 0.8%CVE-2021-34862HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routerEPSS 0.8%