VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,663)

page 158 of 184
  • CVE-2017-7936MedAug 7, 2017
    risk 0.41cvss 6.3epss 0.00

    A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device…

  • CVE-2026-12488MedJun 24, 2026
    risk 0.40cvss 6.2epss 0.00

    A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability.

  • CVE-2024-48519MedMay 13, 2026
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor component.

  • CVE-2026-28897MedMay 11, 2026
    risk 0.40cvss 6.2epss 0.00

    A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause…

  • CVE-2026-33147HigMar 20, 2026
    risk 0.40cvss 7.3epss 0.00

    GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue…

  • CVE-2019-25437MedFeb 20, 2026
    risk 0.40cvss 6.2epss 0.00

    Foscam Video Management System 1.1.6.6 contains a buffer overflow vulnerability in the UID field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 5000-character buffer into the UID parameter during device…

  • CVE-2019-25334MedFeb 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow…

  • CVE-2020-37132MedFeb 5, 2026
    risk 0.40cvss 6.2epss 0.00

    UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and…

  • CVE-2020-37128MedFeb 5, 2026
    risk 0.40cvss 6.2epss 0.00

    ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and…

  • CVE-2025-15555HigFeb 4, 2026
    risk 0.40cvss 7.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer…

  • CVE-2025-65410MedDec 23, 2025
    risk 0.40cvss 6.2epss 0.00

    A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.

  • CVE-2025-12143MedNov 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

  • CVE-2025-12464MedOct 31, 2025
    risk 0.40cvss 6.2epss 0.00

    A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in…

  • CVE-2025-58301MedOct 11, 2025
    risk 0.40cvss 6.2epss 0.00

    Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58300MedOct 11, 2025
    risk 0.40cvss 6.2epss 0.00

    Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-41166MedFeb 12, 2025
    risk 0.40cvss 6.1epss 0.00

    Stack-based buffer overflow in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-7784MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…

  • CVE-2024-38443MedJun 16, 2024
    risk 0.40cvss 6.2epss 0.00

    C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

  • CVE-2024-29421MedMay 22, 2024
    risk 0.40cvss 6.2epss 0.00

    xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.

  • CVE-2024-31803MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT::read_pre_data128_from_file function.