CWE-121
Stack-based Buffer Overflow
Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Hierarchy (View 1000)
CVEs mapped to this weakness (3,602)
page 174 of 181| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16096 | Hig | 0.00 | 8.8 | 0.00 | Jul 18, 2026 | A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is… | ||
| CVE-2026-56455 | Med | 0.00 | 5.3 | 0.00 | Jul 16, 2026 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system… | ||
| CVE-2026-62349 | Hig | 0.00 | 8.3 | 0.00 | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte… | ||
| CVE-2026-51807 | Cri | 0.00 | 9.8 | 0.00 | Jul 14, 2026 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream… | ||
| CVE-2026-47971 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2026-47477 | Hig | 0.00 | 7.5 | 0.00 | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. | ||
| CVE-2026-62655 | Med | 0.00 | — | 0.00 | Jul 14, 2026 | A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable. | ||
| CVE-2026-57091 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56642 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network. | ||
| CVE-2026-55141 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55134 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55055 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55038 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50501 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50412 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50411 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50400 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50387 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50368 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50355 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
- risk 0.00cvss 8.8epss 0.00
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is…
- risk 0.00cvss 5.3epss 0.00
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system…
- risk 0.00cvss 8.3epss 0.00
TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte…
- risk 0.00cvss 9.8epss 0.00
Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream…
- risk 0.00cvss 7.8epss 0.00
Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.00cvss 7.5epss 0.00
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
- risk 0.00cvss —epss 0.00
A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.01
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.02
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.