VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 93 of 182
  • CVE-2020-12497HigJul 1, 2020
    risk 0.52cvss 7.8epss 0.15

    PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

  • CVE-2020-8860HigFeb 22, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2026-19003HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder…

  • CVE-2026-70346HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70344HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-68817HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-68816HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-68795HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-66807HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-64919HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

  • CVE-2026-64912HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

  • CVE-2026-64907HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-63527HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-63526HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62877HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62768HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62755HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

  • CVE-2026-59086HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could…

  • CVE-2026-21068HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

  • CVE-2026-71266HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…