Falhas do tipo CWE-121

3.840 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-32317HIGHTenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSEPSS 0.4%CVE-2026-27821HIGHGPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer OverflowEPSS 0.4%CVE-2024-32316MEDIUMTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.EPSS 0.4%CVE-2024-33213MEDIUMTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goEPSS 0.4%CVE-2026-57163HIGHPJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backendEPSS 0.4%CVE-2024-40417MEDIUMA vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBinEPSS 0.4%CVE-2012-10051HIGHPhotodex ProShow Producer 5.0.3256 load File Handling Buffer OverflowEPSS 0.4%CVE-2026-10064MEDIUMTRENDnet TEW-432BRP formSetPortTr stack-based overflowEPSS 0.4%CVE-2023-38094HIGHKofax Power PDF replacePages Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38092HIGHKofax Power PDF importDataObject Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-47410HIGHAnimate | Stack-based Buffer Overflow (CWE-121)EPSS 0.4%CVE-2023-38093HIGHKofax Power PDF saveAs Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-3729LOWRSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Buffer Overflow vulnerEPSS 0.4%CVE-2024-49350MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2025-32061HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2023-46272HIGHBuffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute EPSS 0.4%CVE-2012-10043CRITICALActFax 4.32 Client Importer Buffer OverflowEPSS 0.4%CVE-2026-49943MEDIUMCZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation inEPSS 0.4%CVE-2023-40484HIGHMaxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-32062HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%