Falhas do tipo CWE-121

3.837 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-67822CRITICALTenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDseEPSS 0.5%CVE-2026-8362CRITICALGladinet Triofox Stack-based Buffer Overflow in WOSDefaultHttpModule.dllEPSS 0.5%CVE-2026-91843CRITICALStack overflow in login process to the Security Management and Log ServersEPSS 0.5%CVE-2024-36468LOWStack buffer overflow in zbx_snmp_cache_handle_engineidEPSS 0.5%CVE-2024-28447MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cEPSS 0.5%CVE-2024-30585MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.EPSS 0.5%CVE-2025-60688MEDIUMA stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router fEPSS 0.5%CVE-2025-50662HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endEPSS 0.5%CVE-2025-60684MEDIUMA stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router fEPSS 0.5%CVE-2025-50663HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endEPSS 0.5%CVE-2024-30586MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.EPSS 0.5%CVE-2025-50660HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp enEPSS 0.5%CVE-2025-50655HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endEPSS 0.5%CVE-2025-50657HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpointEPSS 0.5%CVE-2025-50659HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp EPSS 0.5%CVE-2026-26239MEDIUMFile Station 5EPSS 0.5%CVE-2020-37133MEDIUMUltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of ServiceEPSS 0.5%CVE-2024-23982HIGHBIG-IP PEM vulnerabilityEPSS 0.5%CVE-2026-36778MEDIUMShenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameEPSS 0.5%CVE-2026-11733LOWBuffer overflow vulnerability in some NETGEAR Nighthawk routersEPSS 0.5%