VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 175 of 181
  • CVE-2026-50304HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-4017HigJul 14, 2026
    risk 0.00cvss 7.4epss 0.00

    Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

  • CVE-2026-55899HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-54983HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50695HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50318HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49789HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-15701CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-51105HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.

  • CVE-2026-15696HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has…

  • CVE-2026-15695HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-15694HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public…

  • CVE-2026-15693HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2026-15692HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from…

  • CVE-2026-15691HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out…

  • CVE-2026-40553HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in…

  • CVE-2026-15548HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be…

  • CVE-2026-15544HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely.…

  • CVE-2026-15480HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overflow. The attack can be executed remotely.…

  • CVE-2026-55687HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg_parse_marker.c because the attacker-controlled DQT marker…