VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 115 of 182
  • CVE-2026-33554HigMar 24, 2026
    risk 0.49cvss 7.5epss 0.00

    ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to…

  • CVE-2025-70244HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.

  • CVE-2025-70251HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.

  • CVE-2025-70249HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

  • CVE-2025-70247HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.

  • CVE-2025-70246HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.

  • CVE-2025-70242HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

  • CVE-2025-70227HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.

  • CVE-2025-70250HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

  • CVE-2025-70243HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.

  • CVE-2025-70238HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

  • CVE-2025-69765HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2025-70252HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow…

  • CVE-2025-69700HigFeb 23, 2026
    risk 0.49cvss 7.5epss 0.03

    Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

  • CVE-2019-25434HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field…

  • CVE-2019-25363HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.00

    WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'License Name and License Code' field to…

  • CVE-2019-25341HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98-character buffer into the Domain Name field to trigger an application crash.

  • CVE-2019-25340HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application…

  • CVE-2019-25339HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated characters into the password field to trigger an application crash on iOS devices.

  • CVE-2019-25330HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific…