VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 123 of 191
  • CVE-2025-70242HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

  • CVE-2025-70227HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.

  • CVE-2025-70250HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

  • CVE-2025-70243HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.

  • CVE-2025-70238HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

  • CVE-2025-69765HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2025-70252HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow…

  • CVE-2025-69700HigFeb 23, 2026
    risk 0.49cvss 7.5epss 0.04

    Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

  • CVE-2019-25434HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field…

  • CVE-2019-25363HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.00

    WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'License Name and License Code' field to…

  • CVE-2019-25341HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98-character buffer into the Domain Name field to trigger an application crash.

  • CVE-2019-25340HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application…

  • CVE-2019-25339HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated characters into the password field to trigger an application crash on iOS devices.

  • CVE-2019-25330HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific…

  • CVE-2019-25329HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwriting Structured Exception Handler (SEH) with malicious input. Attackers can generate a payload of 4108 'A' characters followed by 4 'B' characters and 40 'C'…

  • CVE-2019-25328HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application…

  • CVE-2025-67432HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2020-37200HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an…

  • CVE-2020-37198HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into the license activation field to trigger…

  • CVE-2020-37182HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length checking to overwrite memory and cause a segmentation…