Falhas do tipo CWE-121

3.848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-5297MEDIUMSourceCodester Computer Store System main.c Add stack-based overflowEPSS 0.3%CVE-2024-52894MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2025-49589MEDIUMPCSX2 Contains a Stack-based Buffer Overflow in IOP Console LoggingEPSS 0.3%CVE-2026-23747MEDIUMGolioth Firmware SDK < 0.22.0 Payload Utils Stack-based Buffer OverflowEPSS 0.3%CVE-2025-58317HIGHFile Parsing Memory Corruption in CNCSoft-G2EPSS 0.3%CVE-2025-25634MEDIUMA vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The EPSS 0.3%CVE-2019-25318HIGHAVS Audio Converter 9.1.2.600 - Stack OverflowEPSS 0.3%CVE-2024-39354HIGHDelta Electronics DIAScreen Stack-based Buffer OverflowEPSS 0.3%CVE-2019-16641HIGHAn issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.phEPSS 0.3%CVE-2024-30840MEDIUMA Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromEPSS 0.3%CVE-2024-49828MEDIUMIBM Db2 for Linux, UNIX and Windows denial of serviceEPSS 0.3%CVE-2024-47131HIGHDelta Electronics DIAScreen Stack-based Buffer OverflowEPSS 0.3%CVE-2024-47135HIGHStack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6EPSS 0.3%CVE-2024-44390HIGHTenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.EPSS 0.3%CVE-2023-35127HIGHFuji Electric Tellus Lite V-Simulator Stack-based Buffer OverflowEPSS 0.3%CVE-2026-17250HIGHAuthenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update HandlingEPSS 0.3%CVE-2025-1533HIGHA stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading EPSS 0.3%CVE-2024-7539HIGHoFono CUSD Stack-based Buffer Overflow Code Execution VulnerabilityEPSS 0.3%CVE-2025-65223MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.EPSS 0.3%CVE-2025-65221MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.EPSS 0.3%