Falhas do tipo CWE-121

3.850 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-22903MEDIUMTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.EPSS 0.2%CVE-2025-70305MEDIUMA stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.EPSS 0.2%CVE-2023-24549HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2026-2657MEDIUMwren-lang wren Error Message wren_compiler.c printError stack-based overflowEPSS 0.2%CVE-2025-4447HIGHBuffer Overflow in Eclipse OpenJ9EPSS 0.2%CVE-2026-67673MEDIUMA stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when procEPSS 0.2%CVE-2025-23283HIGHNVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stEPSS 0.2%CVE-2024-58116MEDIUMBuffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2024-58115MEDIUMBuffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2024-43031MEDIUMautMan v2.9.6 was discovered to contain an access control issue.EPSS 0.2%CVE-2025-0720MEDIUMMicroword eScan Antivirus Folder Watch List rtscanner removeExtraSlashes stack-based overflowEPSS 0.2%CVE-2024-7994HIGHStack-Based Buffer Overflow Vulnerability in Autodesk RevitEPSS 0.2%CVE-2023-40465HIGHImproper input leads to DoSEPSS 0.2%CVE-2024-7992HIGHAutodesk AutoCAD DWG Stack-Based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2025-36939CRITICALMultiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specEPSS 0.2%CVE-2023-7206HIGHHorner Automation Cscape Stack-Based Buffer OverflowEPSS 0.2%CVE-2023-6340MEDIUMSonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. EPSS 0.2%CVE-2025-70083HIGHAn issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as uEPSS 0.2%CVE-2020-37121MEDIUMCODE::BLOCKS 16.01 - Buffer Overflow (SEH) UNICODEEPSS 0.2%CVE-2026-23995HIGHEVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZEPSS 0.2%