Falhas do tipo CWE-121

3.851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2024-53849MEDIUMSeveral stack buffer overflows and pointer overflows in editorconfig-core-cEPSS 0.2%CVE-2026-59181MEDIUMOpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElementsEPSS 0.2%CVE-2025-62580HIGHASDA-Soft Stack-based Buffer Overflow VulnerabilityEPSS 0.2%CVE-2025-59149MEDIUMSuricata: Stack buffer overflow in rule parser when processing long keywords with transformsEPSS 0.2%CVE-2025-62579HIGHASDA-Soft Stack-based Buffer Overflow VulnerabilityEPSS 0.2%CVE-2022-25334HIGHStack overflow on SK_LOAD signature length field in Texas Instruments OMAP L138EPSS 0.2%CVE-2026-77658HIGHDia: dia: stack buffer overflow in bus object via unvalidated handle count in project filesEPSS 0.2%CVE-2025-12143MEDIUMStack Memory Corruption VulnerabilityEPSS 0.2%CVE-2023-23569HIGHStack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an EPSS 0.2%CVE-2025-59801MEDIUMIn Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel vaEPSS 0.2%CVE-2025-30421HIGHStack-based Buffer Overflow in DrObjectStorage::XML_Serialize() in NI Circuit Design SuiteEPSS 0.2%CVE-2025-48796HIGHGimp: stack-based buffer overflows in file-icoEPSS 0.2%CVE-2026-33147HIGHGMT: Stack-based Buffer Overflow in gmt_remote_dataset_idEPSS 0.2%CVE-2025-59798MEDIUMArtifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.EPSS 0.2%CVE-2026-75142HIGHFFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.cEPSS 0.2%CVE-2025-59799MEDIUMArtifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size vEPSS 0.2%CVE-2025-61856HIGHA stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specialEPSS 0.2%CVE-2026-81433HIGHFireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code ExecutionEPSS 0.2%CVE-2022-2402MEDIUMStack Overflow in ESET Endpoint Encryption and ESET Full Disk Encryption for WindowsEPSS 0.2%CVE-2026-30983HIGHiccDEV has a stack buffer overflow in icFixXml()EPSS 0.2%