VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 12 of 191
  • CVE-2026-24465CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.

  • CVE-2020-37000CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter…

  • CVE-2020-36997CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.00

    BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing…

  • CVE-2020-36967CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute…

  • CVE-2020-36961CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.01

    10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception…

  • CVE-2026-0792CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.01

    ALGO 8180 IP Audio Alerter SIP INVITE Alert-Info Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required…

  • CVE-2026-0791CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.01

    ALGO 8180 IP Audio Alerter SIP INVITE Replaces Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to…

  • CVE-2025-69764CriJan 22, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.

  • CVE-2025-69766CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

  • CVE-2025-69763CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2025-69762CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2023-54334CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH…

  • CVE-2023-54330CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's…

  • CVE-2023-54329CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a…

  • CVE-2026-22214CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The vulnerability occurs in the _handle_char() function, where incoming…

  • CVE-2026-22213CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded…

  • CVE-2026-22189CriJan 7, 2026
    risk 0.64cvss 9.8epss 0.01

    The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph…

  • CVE-2025-34468CriDec 31, 2025
    risk 0.64cvss 9.8epss 0.01

    libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a…

  • CVE-2025-15255CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.05

    A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched…

  • CVE-2025-68706CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.05

    A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks.…