Falhas do tipo CWE-121

3.834 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-50694CRITICALIn SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not EPSS 0.6%CVE-2026-41927HIGHWDR201A WiFi Extender Stack-Based Buffer Overflow via firewall.cgiEPSS 0.6%CVE-2026-43623HIGHmicrotar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()EPSS 0.6%CVE-2025-26688HIGHMicrosoft Virtual Hard Disk Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-77218MEDIUMPLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Credential HandlersEPSS 0.6%CVE-2024-41460MEDIUMTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatEPSS 0.6%CVE-2026-76869HIGHNetcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgiEPSS 0.6%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.6%CVE-2026-55134HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55055HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-25756HIGHA Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to executeEPSS 0.6%CVE-2025-9362MEDIUMLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 urlFilterManageRule stack-based overflowEPSS 0.6%CVE-2026-55038HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-51601HIGHTenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of thEPSS 0.6%CVE-2026-51604HIGHA stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attEPSS 0.6%CVE-2026-51605HIGHA stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote atEPSS 0.6%CVE-2026-62349HIGHTDengine: Off-by-One Buffer OverflowEPSS 0.6%CVE-2024-35580CRITICALTenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.EPSS 0.6%CVE-2024-40535CRITICALShenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the confEPSS 0.6%CVE-2025-25455HIGHTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.EPSS 0.6%