Falhas do tipo CWE-121

3.851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2020-37121MEDIUMCODE::BLOCKS 16.01 - Buffer Overflow (SEH) UNICODEEPSS 0.2%CVE-2026-19003HIGHMongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settingsEPSS 0.2%CVE-2024-23804HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2025-23284HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A sucEPSS 0.2%CVE-2026-50256HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatchEPSS 0.2%CVE-2026-10709HIGHFBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDKEPSS 0.2%CVE-2026-17270MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.2%CVE-2026-10710HIGHFBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDKEPSS 0.2%CVE-2022-31226HIGHDell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this EPSS 0.2%CVE-2024-38309HIGHThere are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS LEPSS 0.2%CVE-2024-4550MEDIUMA potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attackeEPSS 0.2%CVE-2025-3588MEDIUMjoelittlejohn jsonschema2pojo JSON File SchemaRule.java apply stack-based overflowEPSS 0.2%CVE-2026-35553HIGHBluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary codeEPSS 0.2%CVE-2025-60695MEDIUMA stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_40EPSS 0.2%CVE-2020-37013HIGHAudio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)EPSS 0.2%CVE-2021-3434MEDIUML2CAP: Stack based buffer overflow in le_ecred_conn_req()EPSS 0.2%CVE-2023-35986HIGHSantesoft Sante DICOM Viewer Pro Stack-based Buffer OverflowEPSS 0.2%CVE-2024-53849MEDIUMSeveral stack buffer overflows and pointer overflows in editorconfig-core-cEPSS 0.2%CVE-2026-59181MEDIUMOpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElementsEPSS 0.2%CVE-2021-47881MEDIUMdataSIMS Avionics ARINC 664-1 - Local Buffer OverflowEPSS 0.2%