Falhas do tipo CWE-121

3.833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2020-8860HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA,EPSS 0.7%CVE-2025-70237HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.EPSS 0.7%CVE-2025-54480CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%CVE-2025-66048CRITICALSeveral stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A speciaEPSS 0.7%CVE-2025-66043CRITICALSeveral stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A speciaEPSS 0.7%CVE-2023-27346HIGHTP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-1637HIGHTenda AC21 AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflowEPSS 0.7%CVE-2020-37095HIGHCyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)EPSS 0.7%CVE-2025-44893CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post fuEPSS 0.7%CVE-2014-125114HIGHi-Ftp 2.20 Schedule.xml Stack-Based Buffer OverflowEPSS 0.7%CVE-2026-81944HIGHPLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web ServerEPSS 0.7%CVE-2022-23460MEDIUMStack overflow in JsonxxEPSS 0.7%CVE-2026-38422HIGHBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/taEPSS 0.7%CVE-2023-7187MEDIUMTotolink N350RT HTTP POST Request stack-based overflowEPSS 0.7%CVE-2026-90688HIGHTenda W20E HTTP formIPMacBindAdd stack-based overflowEPSS 0.7%CVE-2026-62792HIGHWindows TCP/IP Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-69510HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-69620HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-54489CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%CVE-2025-54481CRITICALA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master BranchEPSS 0.7%