CWE-121
Stack-based Buffer Overflow
Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Hierarchy (View 1000)
CVEs mapped to this weakness (3,626)
page 86 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36965 | Hig | 0.55 | 8.4 | 0.00 | Jan 28, 2026 | docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload that triggers a structured exception handler (SEH) overwrite to execute… | ||
| CVE-2021-47881 | Hig | 0.55 | 8.4 | 0.00 | Jan 23, 2026 | dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to… | ||
| CVE-2025-60696 | Hig | 0.55 | 8.4 | 0.00 | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing results into buffers v6 (12 bytes) and… | ||
| CVE-2025-60692 | Hig | 0.55 | 8.4 | 0.00 | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries… | ||
| CVE-2019-16641 | Hig | 0.55 | 8.4 | 0.00 | Jul 16, 2024 | An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1. | ||
| CVE-2024-37984 | Hig | 0.55 | 8.4 | 0.01 | Jul 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-35333 | Hig | 0.55 | 8.4 | 0.00 | May 29, 2024 | A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially… | ||
| CVE-2024-21474 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when size of buffer from previous call is used without validation or re-initialization. | ||
| CVE-2024-25391 | Hig | 0.55 | 8.4 | 0.00 | Mar 27, 2024 | A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. | ||
| CVE-2024-28582 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format. | ||
| CVE-2024-28581 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format. | ||
| CVE-2024-28580 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format. | ||
| CVE-2024-28566 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format. | ||
| CVE-2023-43549 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption while processing TPC target power table in FTM TPC. | ||
| CVE-2023-28538 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | ||
| CVE-2023-21632 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in Automotive GPU while querying a gsl memory node. | ||
| CVE-2022-40517 | Hig | 0.55 | 8.4 | 0.00 | Jan 9, 2023 | Memory corruption in core due to stack-based buffer overflow | ||
| CVE-2022-40516 | Hig | 0.55 | 8.4 | 0.01 | Jan 9, 2023 | Memory corruption in Core due to stack-based buffer overflow. | ||
| CVE-2021-44703 | Hig | 0.55 | 7.8 | 0.57 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of… | ||
| CVE-2021-33549 | Hig | 0.55 | 7.2 | 0.66 | Sep 13, 2021 | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code. |
- risk 0.55cvss 8.4epss 0.00
docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload that triggers a structured exception handler (SEH) overwrite to execute…
- risk 0.55cvss 8.4epss 0.00
dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to…
- risk 0.55cvss 8.4epss 0.00
A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing results into buffers v6 (12 bytes) and…
- risk 0.55cvss 8.4epss 0.00
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries…
- risk 0.55cvss 8.4epss 0.00
An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1.
- risk 0.55cvss 8.4epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.55cvss 8.4epss 0.00
A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially…
- risk 0.55cvss 8.4epss 0.00
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
- risk 0.55cvss 8.4epss 0.00
A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing TPC target power table in FTM TPC.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive GPU while querying a gsl memory node.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in core due to stack-based buffer overflow
- risk 0.55cvss 8.4epss 0.01
Memory corruption in Core due to stack-based buffer overflow.
- risk 0.55cvss 7.8epss 0.57
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of…
- risk 0.55cvss 7.2epss 0.66
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.