VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 100 of 191
  • CVE-2026-64907HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-63527HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-63526HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62877HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62768HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62755HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

  • CVE-2026-59086HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could…

  • CVE-2026-21068HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

  • CVE-2026-71266HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…

  • CVE-2026-10710HigAug 4, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2026-10709HigAug 4, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current…

  • CVE-2026-5056HigJul 29, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-48389HigJul 20, 2026
    risk 0.51cvss 7.8epss 0.00

    DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-47971HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-49033HigJul 7, 2026
    risk 0.51cvss 7.8epss 0.00

    The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.

  • CVE-2026-47959HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2026-34708HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-34702HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-34697HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-34695HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…