VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 98 of 191
  • CVE-2023-24334HigFeb 21, 2024
    risk 0.52cvss 8.0epss 0.00

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

  • CVE-2023-6749HigFeb 18, 2024
    risk 0.52cvss 8.0epss 0.00

    Unchecked length coming from user input in settings shell

  • CVE-2023-35634HigDec 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Windows Bluetooth Driver Remote Code Execution Vulnerability

  • CVE-2022-24973HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2022-0650HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2023-0656HigMar 2, 2023
    risk 0.52cvss 7.5epss 0.41

    A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

  • CVE-2023-23780HigFeb 16, 2023
    risk 0.52cvss 8.0epss 0.01

    A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests.

  • CVE-2022-27791HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.18

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbitrary code execution in the context of…

  • CVE-2021-44158HigJan 3, 2022
    risk 0.52cvss 8.0epss 0.01

    ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.

  • CVE-2021-22673HigMay 7, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and…

  • CVE-2020-16243HigFeb 23, 2021
    risk 0.52cvss 7.8epss 0.12

    Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. Opening a specially crafted project file could allow an attacker to exploit and execute code under the privileges of the application.

  • CVE-2020-12497HigJul 1, 2020
    risk 0.52cvss 7.8epss 0.15

    PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

  • CVE-2020-8860HigFeb 22, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2026-19477HigSep 17, 2026
    risk 0.51cvss 7.8epss 0.00

    There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior…

  • CVE-2026-83990HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-81953HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-81396HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-81388HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-71337HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

  • CVE-2026-69508HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.