Falhas do tipo CWE-121

3.833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2019-25360HIGHAida64 6.10.5200 - Buffer OverflowEPSS 0.7%CVE-2019-25321HIGHFTP Navigator 8.03 - Stack Overflow (SEH)EPSS 0.7%CVE-2024-30392HIGHJunos OS: MX Series with SPC3 and MS-MPC/-MIC: When URL filtering is enabled and a specific URL request is received a flowd crash occursEPSS 0.7%CVE-2020-27347HIGHtmux stack buffer overflow in function input_csi_dispatch_sgr_colonEPSS 0.7%CVE-2022-23462MEDIUMStack Buffer Overflow in iowowEPSS 0.7%CVE-2017-20205CRITICALValve Source SDK Stack-Based Buffer Overflow RCEEPSS 0.7%CVE-2024-27128MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-27129MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-30606HIGHTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.EPSS 0.7%CVE-2024-30592HIGHTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.EPSS 0.7%CVE-2022-24048HIGHMariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to EPSS 0.7%CVE-2024-28014CRITICALStack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HEPSS 0.7%CVE-2022-37398HIGHA stack-based buffer overflow vulnerability was found on ADMEPSS 0.7%CVE-2025-70242HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.EPSS 0.7%CVE-2024-30607HIGHTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.EPSS 0.7%CVE-2026-10270HIGHD-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflowEPSS 0.7%CVE-2025-32010HIGHA stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP EPSS 0.7%CVE-2026-5684HIGHTenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflowEPSS 0.7%CVE-2024-30591HIGHTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.EPSS 0.7%CVE-2024-30624HIGHTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.EPSS 0.7%