VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 112 of 191
  • CVE-2022-3085HigJan 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code.

  • CVE-2023-21610HigJan 18, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…

  • CVE-2023-21604HigJan 18, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…

  • CVE-2022-3159HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

  • CVE-2022-40201HigJan 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed design (DGN) file is parsed. This may allow an attacker to execute arbitrary code.

  • CVE-2022-42270HigDec 30, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and…

  • CVE-2022-41664HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions < V14.0.0.3), Teamcenter Visualization…

  • CVE-2022-42339HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2022-38450HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2022-3324HigSep 27, 2022
    risk 0.51cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

  • CVE-2022-3296HigSep 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

  • CVE-2022-2896HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

  • CVE-2022-2895HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file.

  • CVE-2022-1888HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-1405HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.02

    CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition.

  • CVE-2021-26635HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.01

    In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such…

  • CVE-2022-22281HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.

  • CVE-2022-27784HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user…

  • CVE-2022-27783HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user…

  • CVE-2021-42532HigMay 2, 2022
    risk 0.51cvss 7.8epss 0.04

    XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.