VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 8 of 181
  • CVE-2025-70240CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

  • CVE-2025-70239CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

  • CVE-2025-70234CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

  • CVE-2025-70241CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

  • CVE-2025-70237CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

  • CVE-2025-70236CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

  • CVE-2026-24497CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: from 7 through 23.

  • CVE-2019-25365CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.00

    ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to…

  • CVE-2019-25364CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.01

    MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.

  • CVE-2019-25361CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell…

  • CVE-2019-25360CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully…

  • CVE-2019-25321CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.01

    FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command…

  • CVE-2019-25319CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger…

  • CVE-2020-37184CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious…

  • CVE-2020-37183CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to…

  • CVE-2020-37181CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite…

  • CVE-2020-37176CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the application's registration dialog to trigger code…

  • CVE-2025-70085CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using…

  • CVE-2026-22904CriFeb 9, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

  • CVE-2026-22903CriFeb 9, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack…