Falhas do tipo CWE-121

3.839 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-71021HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability EPSS 0.4%CVE-2026-93372CRITICALBuffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside tEPSS 0.4%CVE-2025-53022HIGHTrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmwarEPSS 0.4%CVE-2025-69720HIGHThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.EPSS 0.4%CVE-2026-10125HIGHEdimax BR-6478AC POST Request formPPPoESetup stack-based overflowEPSS 0.4%CVE-2026-10121HIGHTRENDnet TEW-432BRP formSetUrlFilter stack-based overflowEPSS 0.4%CVE-2025-70753HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function. This vulnerabilityEPSS 0.4%CVE-2019-25329MEDIUMFTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)EPSS 0.4%CVE-2024-30638MEDIUMTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.EPSS 0.4%CVE-2025-71027HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulEPSS 0.4%CVE-2024-30631MEDIUMTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.EPSS 0.4%CVE-2024-30588MEDIUMTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.EPSS 0.4%CVE-2025-71024HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. ThiEPSS 0.4%CVE-2025-71025HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This EPSS 0.4%CVE-2025-71026HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vEPSS 0.4%CVE-2025-71023HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerEPSS 0.4%CVE-2026-86093HIGHIBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditionsEPSS 0.4%CVE-2025-62858MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2026-101038CRITICALFAST FAC1200R MmtAtePrase stack-based overflowEPSS 0.4%CVE-2026-84351HIGHBuffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer procEPSS 0.4%