Falhas do tipo CWE-121

3.833 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-37635CRITICALTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfgEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2024-32285HIGHTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.EPSS 0.7%CVE-2024-33212HIGHTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goforEPSS 0.7%CVE-2023-6095HIGHRemote Code Execution without authentication using memory overflowEPSS 0.7%CVE-2024-1220HIGHNPort W2150A/W2250A Series Web Server Stack-based Buffer Overflow VulnerabilityEPSS 0.7%CVE-2023-6116HIGHRemote Code Execution without authentication using stack overflowEPSS 0.7%CVE-2024-34946MEDIUMTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcEPSS 0.7%CVE-2024-20521MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Remote Command Execution VulnerabilitiesEPSS 0.7%CVE-2024-54809CRITICALNetgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use ofEPSS 0.7%CVE-2024-32290MEDIUMTenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.EPSS 0.7%CVE-2024-29061HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2026-10666HIGHStack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`EPSS 0.7%CVE-2020-37159HIGHCuckoo Clock 5.0 - Buffer OverflowEPSS 0.7%CVE-2023-4273MEDIUMKernel: exfat: stack overflow in exfat_get_uniname_from_ext_entryEPSS 0.7%CVE-2026-42482HIGHA stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cauEPSS 0.7%CVE-2026-32955HIGHSD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect UEPSS 0.7%CVE-2026-67967CRITICALBuffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVEEPSS 0.6%CVE-2026-78012CRITICALStack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP StackEPSS 0.6%CVE-2023-44015HIGHTenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the sEPSS 0.6%