VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 91 of 191
  • CVE-2024-35333HigMay 29, 2024
    risk 0.55cvss 8.4epss 0.00

    A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially…

  • CVE-2024-21474HigMay 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when size of buffer from previous call is used without validation or re-initialization.

  • CVE-2024-25391HigMar 27, 2024
    risk 0.55cvss 8.4epss 0.00

    A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.

  • CVE-2024-28582HigMar 20, 2024
    risk 0.55cvss 8.4epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.

  • CVE-2024-28581HigMar 20, 2024
    risk 0.55cvss 8.4epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.

  • CVE-2024-28580HigMar 20, 2024
    risk 0.55cvss 8.4epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.

  • CVE-2024-28566HigMar 20, 2024
    risk 0.55cvss 8.4epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.

  • CVE-2023-43549HigMar 4, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while processing TPC target power table in FTM TPC.

  • CVE-2023-28538HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.

  • CVE-2023-21632HigJun 6, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive GPU while querying a gsl memory node.

  • CVE-2022-40517HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in core due to stack-based buffer overflow

  • CVE-2022-40516HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.01

    Memory corruption in Core due to stack-based buffer overflow.

  • CVE-2021-44703HigJan 14, 2022
    risk 0.55cvss 7.8epss 0.57

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of…

  • CVE-2021-33549HigSep 13, 2021
    risk 0.55cvss 7.2epss 0.66

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2018-20247HigDec 24, 2018
    risk 0.55cvss 7.8epss 0.54

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.

  • CVE-2026-84351HigSep 2, 2026
    risk 0.54cvss 8.3epss 0.00

    Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-10898HigJun 4, 2026
    risk 0.54cvss 8.3epss 0.00

    Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-41927HigMay 4, 2026
    risk 0.54cvss —epss 0.01

    WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sending a POST request with a…

  • CVE-2025-26336HigMar 21, 2025
    risk 0.54cvss 8.3epss 0.01

    Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow…

  • CVE-2024-53703HigDec 5, 2024
    risk 0.54cvss 8.1epss 0.13

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.