VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,663)

page 159 of 184
  • CVE-2024-21030MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-28575MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_read_mct() function when reading images in J2K format.

  • CVE-2024-28574MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_copy_default_tcp_and_create_tcd() function when reading images in J2K format.

  • CVE-2024-28573MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile() function when reading images in JPEG format.

  • CVE-2024-28568MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the read_iptc_profile() function when reading images in TIFF format.

  • CVE-2024-28567MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_CreateICCProfile() function when reading images in TIFF format.

  • CVE-2022-1355MedAug 31, 2022
    risk 0.40cvss 6.1epss 0.01

    A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of…

  • CVE-2021-39846MedSep 29, 2021
    risk 0.40cvss 6.1epss 0.03

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the…

  • CVE-2021-39845MedSep 29, 2021
    risk 0.40cvss 6.1epss 0.03

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the…

  • CVE-2021-21556MedJun 14, 2021
    risk 0.40cvss 6.1epss 0.00

    Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to…

  • CVE-2026-0819HigMar 19, 2026
    risk 0.39cvss 7.1epss 0.00

    A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to EncodeAttributes() instead of…

  • CVE-2026-28494HigMar 10, 2026
    risk 0.39cvss 7.1epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are…

  • CVE-2025-0373MedJan 30, 2025
    risk 0.39cvss 6.0epss 0.00

    On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer overflow. A NFS server that exports a cd9660, tarfs, or ext2fs file system can be made to panic by mounting and…

  • CVE-2023-4273MedAug 9, 2023
    risk 0.39cvss 6.0epss 0.01

    A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a…

  • CVE-2022-32493MedOct 12, 2022
    risk 0.39cvss 6.0epss 0.00

    Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2026-63387HigAug 20, 2026
    risk 0.38cvss 7.0epss 0.00

    Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by…

  • CVE-2026-28690MedMar 10, 2026
    risk 0.38cvss 6.9epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with…

  • CVE-2025-60695MedNov 13, 2025
    risk 0.38cvss 5.9epss 0.00

    A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using…

  • CVE-2025-58297MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58295MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.