VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 6 of 191
  • CVE-2026-90823CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.01

    FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted…

  • CVE-2026-91843CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

  • CVE-2026-91001CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The…

  • CVE-2026-90693CriSep 14, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible.

  • CVE-2026-90692CriSep 14, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched…

  • CVE-2026-90680CriSep 14, 2026
    risk 0.64cvss 9.9epss 0.01

    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer…

  • CVE-2026-72982CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69910CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

  • CVE-2026-85509CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

  • CVE-2026-85508CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

  • CVE-2026-85507CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

  • CVE-2026-85506CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

  • CVE-2026-85504CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

  • CVE-2026-78012CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote…

  • CVE-2026-82616CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has…

  • CVE-2026-82593CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-82592CriAug 30, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be…

  • CVE-2026-76071CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can…

  • CVE-2026-76070CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can…

  • CVE-2026-78169CriAug 24, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer…