CWE-121
Stack-based Buffer Overflow
Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Hierarchy (View 1000)
CVEs mapped to this weakness (3,817)
page 91 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-35333 | Hig | 0.55 | 8.4 | 0.00 | May 29, 2024 | A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially… | ||
| CVE-2024-21474 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when size of buffer from previous call is used without validation or re-initialization. | ||
| CVE-2024-25391 | Hig | 0.55 | 8.4 | 0.00 | Mar 27, 2024 | A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. | ||
| CVE-2024-28582 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format. | ||
| CVE-2024-28581 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format. | ||
| CVE-2024-28580 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format. | ||
| CVE-2024-28566 | Hig | 0.55 | 8.4 | 0.00 | Mar 20, 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format. | ||
| CVE-2023-43549 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption while processing TPC target power table in FTM TPC. | ||
| CVE-2023-28538 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | ||
| CVE-2023-21632 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in Automotive GPU while querying a gsl memory node. | ||
| CVE-2022-40517 | Hig | 0.55 | 8.4 | 0.00 | Jan 9, 2023 | Memory corruption in core due to stack-based buffer overflow | ||
| CVE-2022-40516 | Hig | 0.55 | 8.4 | 0.01 | Jan 9, 2023 | Memory corruption in Core due to stack-based buffer overflow. | ||
| CVE-2021-44703 | Hig | 0.55 | 7.8 | 0.57 | Jan 14, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of… | ||
| CVE-2021-33549 | Hig | 0.55 | 7.2 | 0.66 | Sep 13, 2021 | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2018-20247 | Hig | 0.55 | 7.8 | 0.54 | Dec 24, 2018 | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow. | ||
| CVE-2026-84351 | Hig | 0.54 | 8.3 | 0.00 | Sep 2, 2026 | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-10898 | Hig | 0.54 | 8.3 | 0.00 | Jun 4, 2026 | Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-41927 | — | Hig | 0.54 | — | 0.01 | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sending a POST request with a… | |
| CVE-2025-26336 | Hig | 0.54 | 8.3 | 0.01 | Mar 21, 2025 | Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow… | ||
| CVE-2024-53703 | Hig | 0.54 | 8.1 | 0.13 | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. |
- risk 0.55cvss 8.4epss 0.00
A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially…
- risk 0.55cvss 8.4epss 0.00
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
- risk 0.55cvss 8.4epss 0.00
A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
- risk 0.55cvss 8.4epss 0.00
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing TPC target power table in FTM TPC.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive GPU while querying a gsl memory node.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in core due to stack-based buffer overflow
- risk 0.55cvss 8.4epss 0.01
Memory corruption in Core due to stack-based buffer overflow.
- risk 0.55cvss 7.8epss 0.57
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of…
- risk 0.55cvss 7.2epss 0.66
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.
- risk 0.55cvss 7.8epss 0.54
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.
- risk 0.54cvss 8.3epss 0.00
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.54cvss 8.3epss 0.00
Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.54cvss —epss 0.01
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sending a POST request with a…
- risk 0.54cvss 8.3epss 0.01
Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow…
- risk 0.54cvss 8.1epss 0.13
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.