Falhas do tipo CWE-121

3.836 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-82478MEDIUMNASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflowEPSS 0.5%CVE-2023-33028CRITICALBuffer Copy without Checking Size of Input in WLAN FirmwareEPSS 0.5%CVE-2025-69986HIGHA buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate thEPSS 0.5%CVE-2023-50225MEDIUMTP-Link TL-WR902AC dm_fillObjByStr Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-61391HIGHThere is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfEPSS 0.5%CVE-2022-25308—A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the FrEPSS 0.5%CVE-2025-28135HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.EPSS 0.5%CVE-2025-66635HIGHStack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbEPSS 0.5%CVE-2025-48060HIGHAddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)EPSS 0.5%CVE-2026-57166MEDIUMPJSIP: Pre-authentication overflow in the telnet CLI errorEPSS 0.5%CVE-2026-37530HIGHAGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in udEPSS 0.5%CVE-2024-7795HIGHAutel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-45513CRITICALTenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.EPSS 0.5%CVE-2022-3324HIGHStack-based Buffer Overflow in vim/vimEPSS 0.5%CVE-2025-44891CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.EPSS 0.5%CVE-2025-44890CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.EPSS 0.5%CVE-2025-44883CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.EPSS 0.5%CVE-2025-44887CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.EPSS 0.5%CVE-2025-44884CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.EPSS 0.5%CVE-2025-44894CRITICALFW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post fEPSS 0.5%