Falhas do tipo CWE-121

3.851 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2026-21093MEDIUMStack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memorEPSS 0.1%CVE-2024-39556HIGHJunos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflowEPSS 0.1%CVE-2025-53175MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-53172MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-53174MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58301MEDIUMBuffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-53171MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2024-58117MEDIUMStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58300MEDIUMBuffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-58295MEDIUMBuffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-58297MEDIUMBuffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-21807LOWHCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflowEPSS 0.1%CVE-2025-53176LOWStack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the fEPSS 0.1%CVE-2025-58298HIGHData processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-44448MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-38672MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%CVE-2025-47347HIGHStack-based Buffer Overflow in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-20797HIGHIn battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%CVE-2025-20747MEDIUMIn gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege EPSS 0.1%CVE-2025-20749MEDIUMIn charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%