Falhas do tipo CWE-121

3.848 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2021-21573HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%CVE-2023-46720MEDIUMA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 thrEPSS 0.3%CVE-2025-8962MEDIUMcode-projects Hostel Management System Login Form hostel_manage.exe stack-based overflowEPSS 0.3%CVE-2025-8845MEDIUMNASM Netwide Assember nasm.c assemble_file stack-based overflowEPSS 0.3%CVE-2025-8846MEDIUMNASM Netwide Assember parser.c parse_line stack-based overflowEPSS 0.3%CVE-2025-20794MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.3%CVE-2026-6240MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WSEPSS 0.3%CVE-2025-55503HIGHTenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.EPSS 0.3%CVE-2026-6239MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WSEPSS 0.3%CVE-2025-30298HIGHAdobe Framemaker | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2025-27168HIGHIllustrator | Stack-based Buffer Overflow (CWE-121)EPSS 0.3%CVE-2026-2016MEDIUMhappyfish100 libfastcommon base64.c base64_decode stack-based overflowEPSS 0.3%CVE-2024-9745HIGHTungsten Automation Power PDF TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-5295MEDIUMStack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OIDEPSS 0.3%CVE-2025-46398MEDIUMXfig: fig2dev stack-overflow via read_objectsEPSS 0.3%CVE-2024-39480HIGHkdb: Fix buffer overflow during tab-completeEPSS 0.3%CVE-2025-25679HIGHTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.EPSS 0.3%CVE-2022-1888HIGHFuji Electric Alpha7 PC Loader Fuji Electric Alpha7 PC LoaderEPSS 0.3%CVE-2024-1151MEDIUMKernel: stack overflow problem in open vswitch kernel module leading to dosEPSS 0.3%CVE-2024-53311MEDIUMA Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via aEPSS 0.3%