VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 173 of 181
  • CVE-2026-43831HigJul 31, 2026
    risk 0.00cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43829HigJul 31, 2026
    risk 0.00cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-67248HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this…

  • CVE-2026-13309MedJul 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is…

  • CVE-2026-12935HigJul 29, 2026
    risk 0.00cvss epss 0.01

    The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP…

  • CVE-2026-67192HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.01

    Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length…

  • CVE-2026-43771HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

  • CVE-2026-12495MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint,…

  • CVE-2026-55728LowJul 24, 2026
    risk 0.00cvss epss 0.00

    Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially…

  • CVE-2026-16870HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could…

  • CVE-2026-61391HigJul 22, 2026
    risk 0.00cvss 7.2epss 0.00

    There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

  • CVE-2026-59144CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size…

  • CVE-2024-51315CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

  • CVE-2024-51314CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

  • CVE-2024-51312CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

  • CVE-2024-51313CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

  • CVE-2024-51311CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

  • CVE-2026-48389HigJul 20, 2026
    risk 0.00cvss 7.8epss 0.00

    DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-16248HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack…

  • CVE-2026-16097HigJul 18, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is…