← See all resources
Buffer Overflow Attack
Attack Types • Vulnerabilities

Buffer Overflow Attack

How buffer overflow attacks work to execute arbitrary code.

Tags

Buffer OverflowMemoryCode ExecutionExploitation
Download infographic

File: SecPro-ataques-buffer-overflow.gif

What is a buffer overflow?

It is the overflow of a buffer: the program writes more data than fits in the reserved memory region and overwrites whatever follows. If that area holds a function's return address, the attacker can redirect execution to code they control. It is one of the oldest vulnerability classes and still appears in software written in C and C++.

Stack and heap overflows

In a stack overflow the return address or control pointers of the current function are overwritten, giving a direct path to hijacking execution flow. In a heap overflow the dynamic memory management structures are corrupted; exploitation is more indirect but equally feasible.

Protections and how they are bypassed

Modern systems ship stack canaries, DEP/NX to prevent execution in data regions, and ASLR to randomize addresses. They are not infallible: techniques such as ROP reuse fragments of the legitimate code itself to bypass DEP. The real defense is always validating bounds, using safe functions and, where the context allows, memory-safe languages.

More from Attack Types • Vulnerabilities

Explore more infographics

View full catalog

Need help with your cybersecurity? 💬