Falhas do tipo CWE-121

3.850 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-19542MEDIUMStack-based out-of-bounds write in tdelete during tree rebalancingEPSS 0.2%CVE-2022-47936HIGHA vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Parasolid V34.0 (All verEPSS 0.2%CVE-2026-85279HIGHNotepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return ValueEPSS 0.2%CVE-2023-38581HIGHBuffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation EPSS 0.2%CVE-2025-7979HIGHAshlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-15155MEDIUMfloooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflowEPSS 0.2%CVE-2026-14789MEDIUMradareorg radare2 Memory64ListStream mdmp.c stack-based overflowEPSS 0.2%CVE-2025-60686MEDIUMA local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.61EPSS 0.2%CVE-2025-41388HIGHFuji Electric Smart Editor Stack-based Buffer OverflowEPSS 0.2%CVE-2025-60685MEDIUMA stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function).EPSS 0.2%CVE-2023-53879MEDIUMNVClient 5.0 Stack Buffer Overflow Vulnerability via User ConfigurationEPSS 0.2%CVE-2026-50259HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexingEPSS 0.2%CVE-2026-50258HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levelsEPSS 0.2%CVE-2024-43032MEDIUMautMan v2.9.6 allows attackers to bypass authentication via a crafted web request.EPSS 0.2%CVE-2026-25584HIGHiccDEV vulnerable to Stack-based Buffer Overflow in CIccTagFloatNum::GetValues()EPSS 0.2%CVE-2019-25336HIGHSpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)EPSS 0.2%CVE-2023-30900HIGHA vulnerability has been identified in Xpedition Layout Browser (All versions < VX.2.14). Affected application contains a stack overflow vulEPSS 0.2%CVE-2024-21758MEDIUMA stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execEPSS 0.2%CVE-2023-24566LOWA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (AEPSS 0.2%CVE-2025-22903MEDIUMTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.EPSS 0.2%