VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 176 of 181
  • CVE-2026-31267MedJul 9, 2026
    risk 0.00cvss 5.7epss 0.00

    Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with administrative privileges to trigger a system…

  • CVE-2026-51605HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.

  • CVE-2026-51604HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.

  • CVE-2026-51603HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP…

  • CVE-2026-51602HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the…

  • CVE-2026-51601HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard…

  • CVE-2026-60095MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid…

  • CVE-2026-58303MedJul 9, 2026
    risk 0.00cvss 6.1epss 0.00

    Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.

  • CVE-2026-25268HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

  • CVE-2026-41434LowJul 6, 2026
    risk 0.00cvss 3.3epss 0.00

    OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. Version…

  • CVE-2026-14721HigJul 5, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack is…

  • CVE-2026-14606HigJul 3, 2026
    risk 0.00cvss 7.8epss 0.00

    A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipulation results in stack-based…

  • CVE-2026-14605HigJul 3, 2026
    risk 0.00cvss 7.8epss 0.00

    A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buffer overflow. Local access is…

  • CVE-2026-52190HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_448384 component

  • CVE-2026-6687HigJul 1, 2026
    risk 0.00cvss 7.6epss 0.00

    FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:…

  • CVE-2026-43718MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

  • CVE-2026-9105MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.01

    An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the…

  • CVE-2026-13564HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be…

  • CVE-2026-13563HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to…

  • CVE-2026-13539HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The…