Falhas do tipo CWE-121

3.851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-9175MEDIUMneurobin shc shc.c make stack-based overflowEPSS 0.2%CVE-2026-26951MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.2%CVE-2020-37127MEDIUMdnsmasq-utils 2.79-1 - 'dhcp_release' Denial of ServiceEPSS 0.2%CVE-2026-40489HIGHeditorconfig-core-c has incomplete fix for CVE-2023-0341EPSS 0.2%CVE-2025-3916MEDIUMCWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentiallyEPSS 0.2%CVE-2023-25602HIGHA stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earliEPSS 0.2%CVE-2026-42805HIGHA stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser functEPSS 0.2%CVE-2025-40843MEDIUMBuffer overflow in CodeChecker log commandEPSS 0.2%CVE-2024-41902HIGHA vulnerability has been identified in JT2Go (All versions < V2406.0003). The affected application contains a stack-based buffer overflow vuEPSS 0.2%CVE-2024-39779MEDIUMStack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticateEPSS 0.2%CVE-2025-0649HIGHStack Exhaustion In Tensorflow ServingEPSS 0.2%CVE-2018-25360HIGHAgataSoft Auto PingMaster 1.5 Buffer Overflow SEHEPSS 0.2%CVE-2026-45250HIGHStack buffer overflow via setcred(2)EPSS 0.2%CVE-2023-46718MEDIUMA stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 thrEPSS 0.2%CVE-2026-75676HIGHBridge | Stack-based Buffer Overflow (CWE-121)EPSS 0.2%CVE-2026-73070MEDIUMVim: Stack Buffer Overflow in the Vim Socket ServerEPSS 0.2%CVE-2026-28897MEDIUMA buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.EPSS 0.2%CVE-2026-36908MEDIUMA stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers tEPSS 0.2%CVE-2026-49033HIGHStack-Based Buffer Overflow in Labcenter ProteusEPSS 0.2%CVE-2025-24328MEDIUMOAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management networkEPSS 0.2%