CWE-121
Stack-based Buffer Overflow
Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Hierarchy (View 1000)
CVEs mapped to this weakness (3,817)
page 95 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69689 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69503 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69412 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. | ||
| CVE-2026-69301 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-68878 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-68838 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-68834 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-57163 | Cri | 0.52 | 9.1 | 0.00 | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c).… | ||
| CVE-2026-57162 | Cri | 0.52 | 9.1 | 0.01 | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This… | ||
| CVE-2026-12222 | Hig | 0.52 | 8.0 | 0.00 | Jun 15, 2026 | A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer… | ||
| CVE-2026-12221 | Hig | 0.52 | 8.0 | 0.00 | Jun 15, 2026 | A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The… | ||
| CVE-2026-12220 | Hig | 0.52 | 8.0 | 0.00 | Jun 15, 2026 | A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer… | ||
| CVE-2026-12218 | Hig | 0.52 | 8.0 | 0.00 | Jun 15, 2026 | A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow.… | ||
| CVE-2026-30814 | Hig | 0.52 | 8.0 | 0.01 | Apr 8, 2026 | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a… | ||
| CVE-2026-5684 | Hig | 0.52 | 8.0 | 0.01 | Apr 6, 2026 | A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack requires access… | ||
| CVE-2025-60751 | Hig | 0.52 | 7.5 | 0.02 | Oct 21, 2025 | GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. | ||
| CVE-2008-20001 | Hig | 0.52 | — | 0.01 | Aug 30, 2025 | activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable… | ||
| CVE-2013-10057 | Hig | 0.52 | — | 0.02 | Aug 1, 2025 | A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy… | ||
| CVE-2025-40596 | Hig | 0.52 | 7.3 | 0.56 | Jul 23, 2025 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. | ||
| CVE-2025-25679 | Hig | 0.52 | 8.0 | 0.00 | Feb 20, 2025 | Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function. |
- risk 0.52cvss 8.0epss 0.01
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.01
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 9.1epss 0.00
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c).…
- risk 0.52cvss 9.1epss 0.01
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This…
- risk 0.52cvss 8.0epss 0.00
A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer…
- risk 0.52cvss 8.0epss 0.00
A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The…
- risk 0.52cvss 8.0epss 0.00
A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer…
- risk 0.52cvss 8.0epss 0.00
A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow.…
- risk 0.52cvss 8.0epss 0.01
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a…
- risk 0.52cvss 8.0epss 0.01
A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack requires access…
- risk 0.52cvss 7.5epss 0.02
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
- risk 0.52cvss —epss 0.01
activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable…
- risk 0.52cvss —epss 0.02
A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy…
- risk 0.52cvss 7.3epss 0.56
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
- risk 0.52cvss 8.0epss 0.00
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.