Falhas do tipo CWE-121

3.845 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-51383LOWD-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.EPSS 0.4%CVE-2025-60557HIGHD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.EPSS 0.4%CVE-2025-1364MEDIUMMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflowEPSS 0.4%CVE-2026-81533MEDIUMMongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT ValuesEPSS 0.4%CVE-2025-4480MEDIUMcode-projects Simple College Management System Add New Student input stack-based overflowEPSS 0.4%CVE-2026-22321MEDIUMStack-Based Buffer Overflow in CLI Login Username Handling over CLIEPSS 0.4%CVE-2023-5944HIGHDelta Electronics DOPSoft Stack-based Buffer OverflowEPSS 0.4%CVE-2024-39389HIGHAdobe Indesign PDF File Parsing Stack Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-45463HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11578HIGHLuxion KeyShot 3DS File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-50501HIGHWindows Resilient File System (ReFS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-23339LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getEPSS 0.4%CVE-2025-70646HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allEPSS 0.4%CVE-2025-70656HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows EPSS 0.4%CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2025-70650HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg function. This vulnEPSS 0.4%CVE-2025-70744HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability aEPSS 0.4%CVE-2025-70648HIGHTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vulnerability EPSS 0.4%CVE-2025-70651HIGHTenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulEPSS 0.4%CVE-2025-70644HIGHTenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allowsEPSS 0.4%