Falhas do tipo CWE-121

3.836 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-24686HIGHMultiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can EPSS 0.5%CVE-2026-25833HIGHMbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() functionEPSS 0.5%CVE-2026-29974HIGHAn issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided bufferEPSS 0.5%CVE-2026-30364HIGHCentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.EPSS 0.5%CVE-2026-37538HIGHBuffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a denial of service or othEPSS 0.5%CVE-2026-47477HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exEPSS 0.5%CVE-2026-42485HIGHAGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocatesEPSS 0.5%CVE-2026-29068HIGHPJSIP: Stack buffer overflow in Opus codec parserEPSS 0.5%CVE-2026-22790HIGHEVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payloadEPSS 0.5%CVE-2010-10015HIGHAOL <= 9.5 Phobos.Playlist 'Import()' Stack-Based Buffer OverflowEPSS 0.5%CVE-2024-32313MEDIUMTenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting funcEPSS 0.5%CVE-2025-3409MEDIUMNothings stb stb_include_string stack-based overflowEPSS 0.5%CVE-2024-30639MEDIUMTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.EPSS 0.5%CVE-2024-41463MEDIUMTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNaEPSS 0.5%CVE-2024-30629MEDIUMTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.EPSS 0.5%CVE-2026-31971HIGHHTSlib CRAM decoder vulnerable to buffer overflowEPSS 0.5%CVE-2025-54328CRITICALAn issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.5%CVE-2026-31968HIGHHTSlib CRAM decoder vulnerable to buffer overflowEPSS 0.5%CVE-2026-8362CRITICALGladinet Triofox Stack-based Buffer Overflow in WOSDefaultHttpModule.dllEPSS 0.5%CVE-2026-91843CRITICALStack overflow in login process to the Security Management and Log ServersEPSS 0.5%