CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 18 of 79
- CVE-2026-102162HIGHCVSS 8.8EG 8.82026-10-06
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted pa…
- CVE-2026-102302HIGHCVSS 8.8EG 8.82026-09-29
Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-94953HIGHCVSS 8.8EG 8.82026-09-29
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfi…
- CVE-2026-94954HIGHCVSS 8.8EG 8.82026-09-29
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handl…
- CVE-2026-25283HIGHCVSS 8.8EG 8.82026-09-17
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
- CVE-2026-86358HIGHCVSS 8.8EG 8.82026-09-16
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execu…
- CVE-2026-76861HIGHCVSS 8.8EG 8.82026-09-15
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow …
- CVE-2026-76860HIGHCVSS 8.8EG 8.82026-09-15
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stac…
- CVE-2026-76676HIGHCVSS 8.8EG 8.82026-09-15
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's cont…
- CVE-2026-90689HIGHCVSS 8.8EG 8.82026-09-14
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The …
- CVE-2023-46273HIGHCVSS 8.8EG 8.82026-09-14
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
- CVE-2026-73006HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69614HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- CVE-2026-69714HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-78504HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78439HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69759HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69722HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69686HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69762HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69689HIGHCVSS 8.8EG 8.82026-09-08
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69461HIGHCVSS 8.8EG 8.82026-09-08
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- CVE-2026-62706HIGHCVSS 8.8EG 8.82026-09-08
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-81532HIGHCVSS 8.8EG 8.82026-08-28
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not …
- CVE-2026-78910HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-16911HIGHCVSS 8.8EG 8.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
- CVE-2026-16877HIGHCVSS 8.8EG 8.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
- CVE-2026-49420HIGHCVSS 8.8EG 8.82026-08-19
The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet. A host sending crafted RTSP traff…
- CVE-2026-19847HIGHCVSS 8.8EG 8.82026-08-14
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based b…
- CVE-2026-19846HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based b…
- CVE-2026-19845HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to s…
- CVE-2026-19844HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename re…
- CVE-2026-19824HIGHCVSS 8.8EG 8.82026-08-14
A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stac…
- CVE-2026-19823HIGHCVSS 8.8EG 8.82026-08-14
A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex re…
- CVE-2026-19822HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to sta…
- CVE-2026-19815HIGHCVSS 8.8EG 8.82026-08-14
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyw…
- CVE-2026-19814HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-…
- CVE-2026-19813HIGHCVSS 8.8EG 8.82026-08-14
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads…
- CVE-2026-19812HIGHCVSS 8.8EG 8.82026-08-14
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based b…
- CVE-2026-19811HIGHCVSS 8.8EG 8.82026-08-14
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment result…
- CVE-2026-19791HIGHCVSS 8.8EG 8.82026-08-14
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRoute…
- CVE-2026-19790HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPo…
- CVE-2026-19789HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the a…
- CVE-2026-19788HIGHCVSS 8.8EG 8.82026-08-14
A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName resu…
- CVE-2026-13361HIGHCVSS 8.8EG 8.82026-08-12
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
- CVE-2026-62824HIGHCVSS 8.8EG 8.82026-08-11
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2025-15683HIGHCVSS 8.8EG 8.82026-08-10
TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application dat…
- CVE-2026-19341HIGHCVSS 8.8EG 8.82026-08-09
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overf…
- CVE-2026-18898HIGHCVSS 8.8EG 8.82026-08-05
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack …
- CVE-2026-18897HIGHCVSS 8.8EG 8.82026-08-05
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer ove…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →