Falhas do tipo CWE-121

3.848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-35576MEDIUMTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.EPSS 0.3%CVE-2025-6093MEDIUMuYanki board-stm32f103rc-berial heartrate1_hal.c heartrate1_i2c_hal_write stack-based overflowEPSS 0.3%CVE-2026-0413MEDIUMBuffer overflow vulnerability in certain NETGEAR Nighthawk routersEPSS 0.3%CVE-2024-25391HIGHA stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2022-2896HIGHMeasuresoft ScadaPro Server Use After FreeEPSS 0.3%CVE-2025-6170LOWLibxml2: stack buffer overflow in xmllint interactive shell command handlingEPSS 0.3%CVE-2026-36777MEDIUMShenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the param_1 parametEPSS 0.3%CVE-2020-37177MEDIUMBOOTP Turbo 2.0 - Denial of Service (SEH)EPSS 0.3%CVE-2024-4192HIGHStack-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2 DOPSoftEPSS 0.3%CVE-2025-45847MEDIUMALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.EPSS 0.3%CVE-2022-3228MEDIUMUsing custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffeEPSS 0.3%CVE-2024-44386HIGHTenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.EPSS 0.3%CVE-2025-25892MEDIUMA buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnEPSS 0.3%CVE-2025-25891MEDIUMA buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This EPSS 0.3%CVE-2026-92870HIGHA stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termiEPSS 0.3%CVE-2025-64331HIGHSuricata is vulnerable to a stack overflow on large file transfers with http-body-printableEPSS 0.3%CVE-2024-40902HIGHjfs: xattr: fix buffer overflow for invalid xattrEPSS 0.3%CVE-2025-64333HIGHSuricata is vulnerable to a stack overflow from big content-typeEPSS 0.3%CVE-2022-35867HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must first obtain the abiliEPSS 0.3%CVE-2024-41281HIGHLinksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.EPSS 0.3%