VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 40 of 191
  • CVE-2019-17145HigOct 25, 2019
    risk 0.58cvss 8.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-10967HigMay 28, 2019
    risk 0.58cvss 8.8epss 0.04

    In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers,…

  • CVE-2018-17614HigNov 13, 2018
    risk 0.58cvss 8.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT Client prior to V2.7. User interaction is not required to exploit this vulnerability. The specific flaw exists within the parsing of MQTT PUBLISH packets. The…

  • CVE-2018-10636HigAug 13, 2018
    risk 0.58cvss 8.8epss 0.10

    CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an…

  • CVE-2017-15118HigJul 27, 2018
    risk 0.58cvss 8.3epss 0.11

    A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If…

  • CVE-2017-3193HigDec 16, 2017
    risk 0.58cvss 8.8epss 0.06

    Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web administration interface HNAP service.

  • CVE-2026-25283HigSep 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

  • CVE-2026-76861HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute…

  • CVE-2026-76860HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.

  • CVE-2026-90689HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.

  • CVE-2023-46273HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

  • CVE-2026-90558CriSep 12, 2026
    risk 0.57cvss 9.8epss 0.01

    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack…

  • CVE-2026-78504HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

  • CVE-2026-78439HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2026-73006HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69759HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69722HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69686HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69614HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69461HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.