CWE-121
Stack-based Buffer Overflow
Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Hierarchy (View 1000)
CVEs mapped to this weakness (3,817)
page 92 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37296 | Hig | 0.54 | 8.3 | 0.00 | Jan 9, 2024 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | ||
| CVE-2023-40465 | Hig | 0.54 | 8.3 | 0.00 | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal. | ||
| CVE-2023-5055 | Hig | 0.54 | 8.3 | 0.01 | Nov 21, 2023 | Possible variant of CVE-2021-3434 in function le_ecred_reconf_req. | ||
| CVE-2022-41966 | Hig | 0.54 | 8.2 | 0.09 | Dec 28, 2022 | XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code… | ||
| CVE-2020-10064 | Hig | 0.54 | 8.3 | 0.01 | May 25, 2021 | Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gv… | ||
| CVE-2019-5621 | Hig | 0.54 | 7.8 | 0.02 | Apr 29, 2020 | ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | ||
| CVE-2019-5618 | Hig | 0.54 | 7.8 | 0.02 | Apr 29, 2020 | A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | ||
| CVE-2019-17094 | Hig | 0.54 | 8.3 | 0.01 | Jan 27, 2020 | A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions. | ||
| CVE-2018-5410 | Hig | 0.54 | 7.8 | 0.02 | Jan 7, 2019 | Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was… | ||
| CVE-2026-13465 | Hig | 0.53 | 8.1 | 0.00 | Sep 24, 2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. | ||
| CVE-2026-69620 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69510 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-17138 | Hig | 0.53 | 8.1 | 0.00 | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | ||
| CVE-2026-17494 | Hig | 0.53 | 8.2 | 0.00 | Aug 19, 2026 | IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on… | ||
| CVE-2026-17093 | Hig | 0.53 | 8.2 | 0.00 | Aug 19, 2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker… | ||
| CVE-2026-19234 | Hig | 0.53 | 8.2 | 0.00 | Aug 19, 2026 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code… | ||
| CVE-2026-62792 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56766 | Hig | 0.53 | 8.8 | 0.02 | Jun 25, 2026 | Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2… | ||
| CVE-2026-26239 | Hig | 0.53 | 8.1 | 0.01 | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5… | ||
| CVE-2026-29972 | Hig | 0.53 | 8.2 | 0.01 | May 8, 2026 | nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer… |
- risk 0.54cvss 8.3epss 0.00
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
- risk 0.54cvss 8.3epss 0.00
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
- risk 0.54cvss 8.3epss 0.01
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
- risk 0.54cvss 8.2epss 0.09
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code…
- risk 0.54cvss 8.3epss 0.01
Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gv…
- risk 0.54cvss 7.8epss 0.02
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
- risk 0.54cvss 7.8epss 0.02
A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
- risk 0.54cvss 8.3epss 0.01
A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.
- risk 0.54cvss 7.8epss 0.02
Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was…
- risk 0.53cvss 8.1epss 0.00
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
- risk 0.53cvss 8.1epss 0.01
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
- risk 0.53cvss 8.2epss 0.00
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on…
- risk 0.53cvss 8.2epss 0.00
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker…
- risk 0.53cvss 8.2epss 0.00
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code…
- risk 0.53cvss 8.1epss 0.01
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.8epss 0.02
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2…
- risk 0.53cvss 8.1epss 0.01
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5…
- risk 0.53cvss 8.2epss 0.01
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer…