Falhas do tipo CWE-121

3.851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-32259MEDIUMImageMagick has a possible stack buffer overflow in sixel encoderEPSS 0.1%CVE-2026-33452MEDIUMBuffer overflow in Windows clients prior to 14.50EPSS 0.1%CVE-2026-28690MEDIUMImageMagick has a stack write buffer overflow in MNG encoderEPSS 0.1%CVE-2026-2069MEDIUMggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowEPSS 0.1%CVE-2024-45542HIGHStack-based Buffer Overflow in WLAN Windows HostEPSS 0.1%CVE-2025-49010LOWOpenSC: Stack-buffer-overflow WRITE in GET RESPONSEEPSS 0.1%CVE-2026-95818LOWAT_SECURE program buffer overflow via $ORIGIN processingEPSS 0.1%CVE-2025-45375MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.1%CVE-2025-43910LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.1%CVE-2026-33536MEDIUMImageMagick has an Out-of-bounds Write via InterpretImageFilenameEPSS 0.1%CVE-2025-52539HIGHA buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interfaceEPSS 0.1%CVE-2026-10528MEDIUMOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflowEPSS 0.1%CVE-2022-33260MEDIUMStack based buffer overflow in CoreEPSS 0.1%CVE-2026-20509MEDIUMIn Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a mEPSS 0.1%CVE-2022-39129MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%CVE-2022-39106MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2026-19695MEDIUMStack-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-41963LOWStack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-28538HIGHStack-based Buffer Overflow in WIN ProductEPSS 0.1%CVE-2025-20732MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%