VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 95 of 182
  • CVE-2026-32928HigApr 1, 2026
    risk 0.51cvss 7.8epss 0.00

    V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

  • CVE-2026-32925HigApr 1, 2026
    risk 0.51cvss 7.8epss 0.00

    V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

  • CVE-2026-27267HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2026-26738HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

  • CVE-2025-70616HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for code 0x80102058. The vulnerability is caused by missing bounds checking on the user-controlled Options parameter before copying data into a…

  • CVE-2019-25435HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the…

  • CVE-2025-70083HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local buffer DirWithSep using strcpy. The size of this buffer is OS_MAX_PATH_LEN. If…

  • CVE-2026-22923HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with internal data during the PDF export…

  • CVE-2026-1361HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft Stack-based Buffer Overflow Vulnerability

  • CVE-2026-21224HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20797HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID:…

  • CVE-2025-14936HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to exploit this vulnerability…

  • CVE-2025-14934HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to exploit this vulnerability…

  • CVE-2025-14932HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to exploit this vulnerability in…

  • CVE-2025-64469HigDec 18, 2025
    risk 0.51cvss 7.8epss 0.00

    There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user…

  • CVE-2025-54526HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2025-20737HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040.

  • CVE-2025-47360HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing client message during device management.

  • CVE-2025-10925HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.03

    GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2025-5555HigOct 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack.…