VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 119 of 191
  • CVE-2019-12266HigMar 30, 2022
    risk 0.50cvss 7.6epss 0.01

    Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to…

  • CVE-2026-100908HigSep 28, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be…

  • CVE-2026-81944HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.01

    PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to…

  • CVE-2026-33963HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

  • CVE-2026-86093HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a…

  • CVE-2026-88289HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.01

    GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

  • CVE-2026-88287HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.01

    GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

  • CVE-2026-42804HigSep 10, 2026
    risk 0.49cvss 7.6epss 0.00

    A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function…

  • CVE-2026-77101HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

  • CVE-2026-67560HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function,…

  • CVE-2026-68863HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2026-75368HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.

  • CVE-2026-76879HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-73522HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.04

    COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function…

  • CVE-2026-20345HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of…

  • CVE-2026-67866HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path

  • CVE-2026-71265HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches…

  • CVE-2026-15722HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.01

    A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated…

  • CVE-2026-43832HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43831HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.