CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 19 of 79
- CVE-2026-18895HIGHCVSS 8.8EG 8.82026-08-05
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is poss…
- CVE-2026-18607HIGHCVSS 8.8EG 8.82026-08-03
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the fil…
- CVE-2026-67248HIGHCVSS 8.8EG 8.82026-07-30
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An auth…
- CVE-2026-16870HIGHCVSS 8.8EG 8.82026-07-24
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execut…
- CVE-2026-64831HIGHCVSS 8.8EG 8.82026-07-22
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bit…
- CVE-2026-16418HIGHCVSS 8.8EG 8.82026-07-21
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-16248HIGHCVSS 8.8EG 8.82026-07-20
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in …
- CVE-2026-16097HIGHCVSS 8.8EG 8.82026-07-18
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to laun…
- CVE-2026-16096HIGHCVSS 8.8EG 8.82026-07-18
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate t…
- CVE-2026-56642HIGHCVSS 8.8EG 8.82026-07-14
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
- CVE-2026-15696HIGHCVSS 8.8EG 8.82026-07-14
A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can b…
- CVE-2026-15695HIGHCVSS 8.8EG 8.82026-07-14
A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be i…
- CVE-2026-15694HIGHCVSS 8.8EG 8.82026-07-14
A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the at…
- CVE-2026-15693HIGHCVSS 8.8EG 8.82026-07-14
A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It i…
- CVE-2026-15692HIGHCVSS 8.8EG 8.82026-07-14
A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflo…
- CVE-2026-15691HIGHCVSS 8.8EG 8.82026-07-14
A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. …
- CVE-2026-15548HIGHCVSS 8.8EG 8.82026-07-13
A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer o…
- CVE-2026-15544HIGHCVSS 8.8EG 8.82026-07-13
A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow…
- CVE-2026-15480HIGHCVSS 8.8EG 8.82026-07-12
A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overflo…
- CVE-2026-25268HIGHCVSS 8.8EG 8.82026-07-06
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
- CVE-2026-14721HIGHCVSS 8.8EG 8.82026-07-05
A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-ba…
- CVE-2026-13564HIGHCVSS 8.8EG 8.82026-06-29
A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-b…
- CVE-2026-13563HIGHCVSS 8.8EG 8.82026-06-29
A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based …
- CVE-2026-13539HIGHCVSS 8.8EG 8.82026-06-29
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid l…
- CVE-2026-13519HIGHCVSS 8.8EG 8.82026-06-29
A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be exec…
- CVE-2026-13518HIGHCVSS 8.8EG 8.82026-06-29
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the atta…
- CVE-2026-13517HIGHCVSS 8.8EG 8.82026-06-29
A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The att…
- CVE-2026-13516HIGHCVSS 8.8EG 8.82026-06-28
A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overfl…
- CVE-2026-13515HIGHCVSS 8.8EG 8.82026-06-28
A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The att…
- CVE-2026-56766HIGHCVSS 8.8EG 8.82026-06-25
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicio…
- CVE-2026-48715HIGHCVSS 8.8EG 8.82026-06-19
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisemen…
- CVE-2026-55738HIGHCVSS 8.8EG 8.82026-06-17
A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the …
- CVE-2026-45648HIGHCVSS 8.8EG 8.82026-06-09
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- CVE-2026-11557HIGHCVSS 8.8EG 8.82026-06-08
A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead …
- CVE-2026-11553HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack …
- CVE-2026-11528HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-b…
- CVE-2026-11524HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRema…
- CVE-2026-11523HIGHCVSS 8.8EG 8.82026-06-08
A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-base…
- CVE-2026-11522HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buf…
- CVE-2026-11504HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument …
- CVE-2026-11503HIGHCVSS 8.8EG 8.82026-06-08
A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi Configuration Endpoint. Such manipulati…
- CVE-2026-11498HIGHCVSS 8.8EG 8.82026-06-08
A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of th…
- CVE-2026-11413HIGHCVSS 8.8EG 8.82026-06-06
A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stack-based buffer overflow. It is possible …
- CVE-2026-11024HIGHCVSS 8.8EG 8.82026-06-04
Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-35085HIGHCVSS 8.8EG 8.82026-06-03
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
- CVE-2026-35084HIGHCVSS 8.8EG 8.82026-06-03
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
- CVE-2026-35083HIGHCVSS 8.8EG 8.82026-06-03
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
- CVE-2026-10293HIGHCVSS 8.8EG 8.82026-06-01
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow. Remote exploitation of the attac…
- CVE-2026-10292HIGHCVSS 8.8EG 8.82026-06-01
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The explo…
- CVE-2026-43623HIGHCVSS 8.8EG 8.82026-06-01
microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a crafted TAR archive with non-null-terminate…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →