VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 168 of 181
  • CVE-2026-20797MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.01

    A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

  • CVE-2025-43374MedNov 21, 2025
    risk 0.28cvss 4.3epss 0.00

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able…

  • CVE-2025-65223MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

  • CVE-2025-65222MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.02

    Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

  • CVE-2025-65221MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

  • CVE-2025-65220MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

  • CVE-2025-59801MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.

  • CVE-2025-59799MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

  • CVE-2025-59798MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

  • CVE-2025-3203MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation of the argument Password leads to stack-based buffer overflow. The attack can be…

  • CVE-2025-1758MedMar 19, 2025
    risk 0.28cvss 4.3epss 0.05

    Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

  • CVE-2024-12352MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-43032MedAug 23, 2024
    risk 0.28cvss 4.3epss 0.00

    autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.

  • CVE-2024-43031MedAug 23, 2024
    risk 0.28cvss 4.3epss 0.00

    autMan v2.9.6 was discovered to contain an access control issue.

  • CVE-2024-40723MedAug 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the…

  • CVE-2024-40722MedAug 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the…

  • CVE-2023-48906MedApr 1, 2024
    risk 0.28cvss 4.3epss 0.00

    Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

  • CVE-2024-30638MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.

  • CVE-2024-30631MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.

  • CVE-2024-30588MedMar 28, 2024
    risk 0.28cvss 4.3epss 0.00

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.