Falhas do tipo CWE-121

3.837 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-60569HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.EPSS 0.5%CVE-2025-70223CRITICALStack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.EPSS 0.5%CVE-2025-57217MEDIUMTenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WeEPSS 0.5%CVE-2024-53695MEDIUMHBS 3 Hybrid Backup SyncEPSS 0.5%CVE-2026-16870HIGHMultiple Security Vulnerabilities in Snowflake libsnowflakeclientEPSS 0.5%CVE-2024-28446MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_netmask parameter at /apply.cEPSS 0.5%CVE-2010-20007HIGHSeagull FTP v3.3 Build 409 Stack Buffer OverflowEPSS 0.5%CVE-2011-10027HIGHAOL Desktop 9.6 RTX Stack-Based Buffer OverflowEPSS 0.5%CVE-2010-20034HIGHGekko Manager FTP Client <= 0.77 Stack Buffer OverflowEPSS 0.5%CVE-2010-20108HIGHFTPPad <= 1.2.0 Stack Buffer OverflowEPSS 0.5%CVE-2024-33513MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.5%CVE-2024-30603MEDIUMTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.EPSS 0.5%CVE-2010-20107HIGHFTP Synchronizer Professional <= 4.0.73.274 Stack Buffer OverflowEPSS 0.5%CVE-2026-26269MEDIUMVim has a Netbeans specialKeys Stack Buffer OverflowEPSS 0.5%CVE-2025-34457HIGHwb2osz/direwolf <= 1.8.1 Stack-based Buffer Overflow DoSEPSS 0.5%CVE-2026-11735LOWStack-based buffer overflow vulnerability in some NETGEAR Nighthawk modelsEPSS 0.5%CVE-2019-17094HIGHStack-Based Overflow vulnerability in Belkin WeMo Insights SwitchEPSS 0.5%CVE-2026-22189MEDIUMPanda3D <= 1.10.16 egg-mkfont Stack Buffer OverflowEPSS 0.5%CVE-2024-32287MEDIUMTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.EPSS 0.5%CVE-2025-45841MEDIUMTOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg fuEPSS 0.5%