Falhas do tipo CWE-121

3.834 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-3482CRITICALMedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2180HIGHTenda RX3 fast_setting_wifi_set stack-based overflowEPSS 0.6%CVE-2025-57218MEDIUMTenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sEPSS 0.6%CVE-2024-34203LOWTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.EPSS 0.6%CVE-2020-37126HIGHFree Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)EPSS 0.6%CVE-2026-28848HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacEPSS 0.6%CVE-2025-53843MEDIUMA stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, EPSS 0.6%CVE-2026-58158HIGHApache Traffic Server: PROXY protocol parsing has port truncation and a stack overflowEPSS 0.6%CVE-2026-33930HIGHApache Traffic Server: Buffer overflow via Host field that has a long string valueEPSS 0.6%CVE-2026-71979HIGHINDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag ParsingEPSS 0.6%CVE-2018-11447—A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request ForgEPSS 0.6%CVE-2026-96257CRITICALFast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflowEPSS 0.6%CVE-2025-70227HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.EPSS 0.6%CVE-2025-70246HIGHStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.EPSS 0.6%CVE-2023-44448MEDIUMTP-Link Archer A54 libcmm.so dm_fillObjByStr Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-52162MEDIUMMercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attaEPSS 0.6%CVE-2025-3483CRITICALMedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-3481CRITICALMedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-38433MEDIUMRTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer OverflowEPSS 0.6%CVE-2026-9150MEDIUMLibsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksumsEPSS 0.6%