Falhas do tipo CWE-121

3.845 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-60547HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.EPSS 0.4%CVE-2025-60559HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.EPSS 0.4%CVE-2025-60568HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.EPSS 0.4%CVE-2025-60555HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.EPSS 0.4%CVE-2020-37066HIGHGoldWave 5.70 – Buffer Overflow (SEH Unicode)EPSS 0.4%CVE-2025-60565HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.EPSS 0.4%CVE-2025-60558HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.EPSS 0.4%CVE-2025-6072HIGHStack Buffer Overflow in MQTTCoreEPSS 0.4%CVE-2025-60551HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.EPSS 0.4%CVE-2025-60562HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.EPSS 0.4%CVE-2025-60563HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.EPSS 0.4%CVE-2025-60556HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.EPSS 0.4%CVE-2025-60549HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.EPSS 0.4%CVE-2025-60552HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.EPSS 0.4%CVE-2025-60550HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.EPSS 0.4%CVE-2025-11786HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11782HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11784HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-11785HIGHStack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2025-4471MEDIUMcode-projects Jewelery Store Management system Search Item View stack-based overflowEPSS 0.4%