Falhas do tipo CWE-121

3.845 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-12222HIGHYealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflowEPSS 0.4%CVE-2014-5407—Schneider Electric VAMPSET Stack-based Buffer OverflowEPSS 0.4%CVE-2026-12220HIGHYealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflowEPSS 0.4%CVE-2025-63154HIGHTOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. ThisEPSS 0.4%CVE-2026-12218HIGHYealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflowEPSS 0.4%CVE-2025-63153HIGHTOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnEPSS 0.4%CVE-2026-12221HIGHYealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflowEPSS 0.4%CVE-2025-63456MEDIUMTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability aEPSS 0.4%CVE-2025-65805HIGHOpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch aEPSS 0.4%CVE-2025-63457MEDIUMTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. This vulnerability allEPSS 0.4%CVE-2025-63458HIGHTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. ThiEPSS 0.4%CVE-2025-63149HIGHTenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. ThisEPSS 0.4%CVE-2025-63454HIGHTenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info functionEPSS 0.4%CVE-2026-6637HIGHPostgreSQL refint allows stack buffer overflow and SQL injectionEPSS 0.4%CVE-2025-63152HIGHTenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. ThEPSS 0.4%CVE-2025-63147MEDIUMTenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlInfo function. This vEPSS 0.4%CVE-2011-10014HIGHGTA SA-MP server.cfg Buffer OverflowEPSS 0.4%CVE-2025-51384LOWD-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.EPSS 0.4%CVE-2025-64332HIGHSuricata is vulnerable to a stack overflow on larger compressed dataEPSS 0.4%CVE-2018-10601—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%