Fallos del tipo CWE-121

3827 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2024-28898MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2025-60474HIGHA buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to causEPSS 0.8%CVE-2023-46553HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.EPSS 0.8%CVE-2024-30595CRITICALTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.EPSS 0.8%CVE-2026-61486CRITICALApache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed inputEPSS 0.8%CVE-2024-30622CRITICALTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.EPSS 0.8%CVE-2023-46559HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.EPSS 0.8%CVE-2024-30628CRITICALTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.EPSS 0.8%CVE-2023-46552HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.EPSS 0.8%CVE-2023-46563HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.EPSS 0.8%CVE-2023-46560HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.EPSS 0.8%CVE-2023-46562HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.EPSS 0.8%CVE-2020-10064HIGHImproper Input Frame Validation in ieee802154 ProcessingEPSS 0.8%CVE-2023-46564HIGHTOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.EPSS 0.8%CVE-2026-9481HIGHEdimax EW-7438RPn formStats stack-based overflowEPSS 0.8%CVE-2026-9463HIGHEdimax EW-7438RPn formLicence stack-based overflowEPSS 0.8%CVE-2020-10639—Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A EPSS 0.8%CVE-2026-9461HIGHEdimax EW-7438RPn formRadius stack-based overflowEPSS 0.8%CVE-2026-4167HIGHBelkin F9K1122 formReboot stack-based overflowEPSS 0.8%CVE-2026-8234HIGHEFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflowEPSS 0.8%