Fallos del tipo CWE-121

3828 resultados

Estouro de buffer na pilha

Ocorre quando código escreve dados além dos limites de um buffer alocado na pilha (stack), sobrescrevendo informações críticas como endereços de retorno ou variáveis locais. Um atacante pode explorar isso para executar código arbitrário ou causar crash da aplicação.

Ejemplo

Uma função copia uma string de entrada diretamente em um array de 64 bytes sem validar o tamanho: `char buffer[64]; strcpy(buffer, user_input);` Se o usuário enviar uma string com 200 bytes, ela sobrescreverá o endereço de retorno e pode redirecionar a execução para código malicioso.

Cómo mitigar

Use funções seguras com limite de tamanho (`strncpy`, `snprintf`), valide e sanitize entradas antes de copiar, implemente proteções em tempo de execução (stack canaries, ASLR, DEP) e considere usar linguagens com verificação de limites automática quando possível.

CVE-2023-39277— SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to aEPSS 0.8%CVE-2023-39278—SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crashEPSS 0.8%CVE-2023-41712—SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.EPSS 0.8%CVE-2023-39279—SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crashEPSS 0.8%CVE-2023-39280—SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewEPSS 0.8%CVE-2023-39276— SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. EPSS 0.8%CVE-2025-3266MEDIUMqinguoyi TinyWebServer http_conn.cpp stack-based overflowEPSS 0.8%CVE-2026-45538CRITICALOpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name CopyEPSS 0.8%CVE-2026-16885CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.8%CVE-2026-41565HIGHCryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpersEPSS 0.8%CVE-2025-11123HIGHTenda AC18 saveAutoQos stack-based overflowEPSS 0.8%CVE-2026-90779HIGHSIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm ParameterEPSS 0.8%CVE-2025-11122HIGHTenda AC18 WizardHandle stack-based overflowEPSS 0.8%CVE-2026-16872CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.8%CVE-2025-11526HIGHTenda AC7 WifiMacFilterSet stack-based overflowEPSS 0.8%CVE-2024-41882MEDIUMStack based buffer overflowEPSS 0.8%CVE-2025-6566MEDIUMoatpp Oat++ Deserializer.cpp deserializeArray stack-based overflowEPSS 0.8%CVE-2025-12214HIGHTenda O3 sysAutoReboot GetValue stack-based overflowEPSS 0.8%CVE-2025-11387HIGHTenda AC15 fast_setting_pppoe_set stack-based overflowEPSS 0.8%CVE-2025-11325HIGHTenda AC18 fast_setting_pppoe_set stack-based overflowEPSS 0.8%