Falhas do tipo CWE-121

3.833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2017-16332HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16310HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16275HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16335HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16308HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2017-16278HIGHMultiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmwarEPSS 0.7%CVE-2026-51807CRITICALHeap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caEPSS 0.7%CVE-2024-37634CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.EPSS 0.7%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 0.7%CVE-2026-59837MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2,EPSS 0.7%CVE-2020-37138HIGH10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)EPSS 0.7%CVE-2024-30612HIGHTenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState funcEPSS 0.7%CVE-2025-60679HIGHA stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cEPSS 0.7%CVE-2025-40634CRITICALStack-based buffer overflow in TP-Link Archer AX50EPSS 0.7%CVE-2026-58181HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crashEPSS 0.7%CVE-2024-30394HIGHJunos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crashEPSS 0.7%CVE-2026-58180HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker inputEPSS 0.7%CVE-2025-14423HIGHGIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-37635CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfgEPSS 0.7%CVE-2026-67379HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.7%