Falhas do tipo CWE-121

3.825 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2023-41215HIGHD-Link DAP-2622 DDP Set Date-Time Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-14133HIGHLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wireless_clientlist_setClientsName stack-based overflowEPSS 0.9%CVE-2025-14134HIGHLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflowEPSS 0.9%CVE-2025-54820HIGHA Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 throughEPSS 0.9%CVE-2025-14135HIGHLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wired_clientlist_setClientsName stack-based overflowEPSS 0.9%CVE-2023-51566HIGHKofax Power PDF OXPS File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-10351HIGHTenda RX9 Pro POST Request setMacFilterCfg sub_424CE0 stack-based overflowEPSS 0.9%CVE-2021-44432—A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected prEPSS 0.9%CVE-2026-28846HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5EPSS 0.9%CVE-2025-15179HIGHTenda WH450 qossetting stack-based overflowEPSS 0.9%CVE-2021-44435—A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected prEPSS 0.9%CVE-2019-25364CRITICALWin10 MailCarrier 2.51 - 'POP3 User' Remote Buffer OverflowEPSS 0.9%CVE-2009-10006CRITICALUFO: Alien Invasion <= 2.2.1 IRC Client Buffer OverflowEPSS 0.9%CVE-2025-15160HIGHTenda WH450 PPTPServer stack-based overflowEPSS 0.9%CVE-2025-11586HIGHTenda AC7 setNotUpgrade stack-based overflowEPSS 0.9%CVE-2025-7505HIGHTenda FH451 HTTP POST Request L7Prot frmL7ProtForm stack-based overflowEPSS 0.9%CVE-2025-7506HIGHTenda FH451 HTTP POST Request Natlimit fromNatlimit stack-based overflowEPSS 0.9%CVE-2025-7806HIGHTenda FH451 SafeClientFilter fromSafeClientFilter stack-based overflowEPSS 0.9%CVE-2025-7807HIGHTenda FH451 SafeUrlFilter fromSafeUrlFilter stack-based overflowEPSS 0.9%CVE-2025-7805HIGHTenda FH451 PPTPUserSetting fromPptpUserSetting stack-based overflowEPSS 0.9%