Falhas do tipo CWE-121

3.828 resultados

Estouro de buffer na pilha

Ocorre quando código escreve mais dados em um buffer alocado na pilha do que sua capacidade permite, sobrescrevendo dados adjacentes (variáveis, endereços de retorno). Um atacante pode explorar isso para executar código arbitrário ou crashar a aplicação alterando o fluxo de execução.

Exemplo

Uma função C que copia uma string do usuário diretamente em um array local sem validar tamanho: `char buffer[10]; strcpy(buffer, user_input);`. Se user_input tiver 50 caracteres, os 40 extras sobrescrevem a pilha, incluindo potencialmente o endereço de retorno da função.

Como mitigar

Use funções seguras que limitam escrita (strncpy, snprintf em vez de strcpy/sprintf), valide tamanho de entrada antes de copiar, ative proteções do compilador (stack canaries, ASLR) e use ferramentas de análise estática para detectar cópias sem limite.

CVE-2025-11388HIGHTenda AC15 setNotUpgrade stack-based overflowEPSS 0.8%CVE-2025-12214HIGHTenda O3 sysAutoReboot GetValue stack-based overflowEPSS 0.8%CVE-2025-12213HIGHTenda O3 setVlanConfig GetValue stack-based overflowEPSS 0.8%CVE-2025-12212HIGHTenda O3 setNetworkService GetValue stack-based overflowEPSS 0.8%CVE-2025-11527HIGHTenda AC7 fast_setting_pppoe_set stack-based overflowEPSS 0.8%CVE-2025-11528HIGHTenda AC7 saveAutoQos stack-based overflowEPSS 0.8%CVE-2010-20049CRITICALLeapFTP < 3.1.x Stack Buffer OverflowEPSS 0.8%CVE-2022-1669MEDIUMCircutor COMPACT DC-S BASICEPSS 0.8%CVE-2024-0540MEDIUMTenda W9 httpd formOfflineSet stack-based overflowEPSS 0.8%CVE-2024-34207HIGHTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.EPSS 0.8%CVE-2025-69766CRITICALTenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag sEPSS 0.8%CVE-2024-20336MEDIUMA vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, EPSS 0.8%CVE-2024-57440HIGHD-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgiEPSS 0.8%CVE-2026-6196HIGHTenda F456 exeCommand fromexeCommand stack-based overflowEPSS 0.8%CVE-2026-78169CRITICALUTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflowEPSS 0.8%CVE-2026-6194HIGHTotolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflowEPSS 0.8%CVE-2026-6168HIGHTOTOLINK A7000R cstecgi.cgi setWiFiEasyGuestCfg stack-based overflowEPSS 0.8%CVE-2026-78050CRITICALComfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflowEPSS 0.8%CVE-2026-6199HIGHTenda F456 qossetting fromqossetting stack-based overflowEPSS 0.8%CVE-2026-76004CRITICALUTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflowEPSS 0.8%