Falhas do tipo CWE-121

3.848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-76879HIGHStack-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2022-23006LOWBuffer Overflow Vulnerability in Western Digital My Cloud Home Products and SanDisk ibiEPSS 0.3%CVE-2026-7866CRITICALStack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.EPSS 0.3%CVE-2026-33307HIGHmod_gnutils has stack-based buffer overflow caused by a long client certificate chainEPSS 0.3%CVE-2026-44089CRITICALBuffer Overflow in Totolink EX1200L routerEPSS 0.3%CVE-2026-100745MEDIUMEdimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflowEPSS 0.3%CVE-2023-3043CRITICALStack-based Buffer Overflow BMCEPSS 0.3%CVE-2023-37293CRITICALstack-based buffer overflow EPSS 0.3%CVE-2023-4756MEDIUMStack-based Buffer Overflow in gpac/gpacEPSS 0.3%CVE-2026-102302HIGHBuffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a cEPSS 0.3%CVE-2022-2895HIGHMeasuresoft ScadaPro Server Stack-based Buffer OverflowEPSS 0.3%CVE-2026-1950CRITICALNo checking of the length of the buffer with the file name in AS320TEPSS 0.3%CVE-2024-11609HIGHAutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-5602HIGHStack-based Buffer Overflow Vulnerability in NI I/O Trace ToolEPSS 0.3%CVE-2021-21556MEDIUMDell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerabilEPSS 0.3%CVE-2024-29756CRITICALIn afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privileEPSS 0.3%CVE-2026-1871HIGHAuthenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200EPSS 0.3%CVE-2023-37331HIGHKofax Power PDF GIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-28136MEDIUMTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.EPSS 0.3%CVE-2026-44056MEDIUMStack buffer overflow in desktop.cEPSS 0.3%