CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 39 of 79
- CVE-2026-85384HIGHCVSS 8.5EG 8.52026-09-08
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local net…
- CVE-2026-67379HIGHCVSS 8.5EG 8.52026-09-08
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68960HIGHCVSS 8.5EG 8.52026-08-25
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to ex…
- CVE-2026-17250HIGHCVSS 8.5EG 8.52026-08-21
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authentica…
- CVE-2010-20107HIGHCVSS 8.5EG 8.52025-08-21
A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response contain…
- CVE-2010-20034HIGHCVSS 8.5EG 8.52025-08-21
Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate the length of filenames. A crafted resp…
- CVE-2010-20007HIGHCVSS 8.5EG 8.52025-08-21
Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excess…
- CVE-2010-20045HIGHCVSS 8.5EG 8.52025-08-20
FileWrangler <= 5.30 suffers from a stack-based buffer overflow vulnerability when parsing directory listings from an FTP server. A malicious server can send an overlong folder name in response to a LIST command, triggering memory corrupti…
- CVE-2026-20521HIGHCVSS 8.4EG 8.42026-10-05
In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patc…
- CVE-2026-42805HIGHCVSS 8.4EG 8.42026-09-10
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and…
- CVE-2026-82079HIGHCVSS 8.4EG 8.42026-09-10
A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted networ…
- CVE-2026-16832HIGHCVSS 8.4EG 8.42026-08-19
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC adminis…
- CVE-2026-45463HIGHCVSS 8.4EG 8.42026-06-09
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2018-25383HIGHCVSS 8.4EG 8.42026-05-29
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA fil…
- CVE-2018-25344HIGHCVSS 8.4EG 8.42026-05-26
10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite…
- CVE-2018-25375HIGHCVSS 8.4EG 8.42026-05-25
SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious inp…
- CVE-2018-25373HIGHCVSS 8.4EG 8.42026-05-25
SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers…
- CVE-2018-25360HIGHCVSS 8.4EG 8.42026-05-25
AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a …
- CVE-2018-25322HIGHCVSS 8.4EG 8.42026-05-17
Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk …
- CVE-2020-37221HIGHCVSS 8.4EG 8.42026-05-13
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a b…
- CVE-2026-30363HIGHCVSS 8.4EG 8.42026-05-01
flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.
- CVE-2018-25303HIGHCVSS 8.4EG 8.42026-04-29
Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers…
- CVE-2026-5726HIGHCVSS 8.4EG 8.42026-04-08
ASDA-Soft Stack-based Buffer Overflow Vulnerability
- CVE-2019-25357HIGHCVSS 8.4EG 8.42026-02-18
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload excee…
- CVE-2019-25332HIGHCVSS 8.4EG 8.42026-02-12
FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to o…
- CVE-2019-25331HIGHCVSS 8.4EG 8.42026-02-12
AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes …
- CVE-2020-37142HIGHCVSS 8.4EG 8.42026-02-05
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting t…
- CVE-2026-0660HIGHCVSS 8.4EG 8.42026-02-04
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- CVE-2020-37013HIGHCVSS 8.4EG 8.42026-01-29
Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters that allows attackers to execute arbitrary code. Attackers can craft malicious payloads and overwrite Structured Exceptio…
- CVE-2020-37001HIGHCVSS 8.4EG 8.42026-01-29
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that…
- CVE-2020-36971HIGHCVSS 8.4EG 8.42026-01-28
Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration parameter. Attackers can craft a malicious payload and paste it into the 'License Code' field to execute arbitrary code on…
- CVE-2020-36965HIGHCVSS 8.4EG 8.42026-01-28
docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload that triggers a structured exceptio…
- CVE-2021-47881HIGHCVSS 8.4EG 8.42026-01-23
dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constru…
- CVE-2025-60696HIGHCVSS 8.4EG 8.42025-11-13
A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing…
- CVE-2025-60692HIGHCVSS 8.4EG 8.42025-11-13
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%…
- CVE-2010-20123HIGHCVSS 8.4EG 8.42025-08-21
Steinberg MyMP3Player version 3.0 (build 3.0.0.67) is vulnerable to a stack-based buffer overflow when parsing .m3u playlist files. The application fails to properly validate the length of input data within the playlist, allowing a special…
- CVE-2010-20114HIGHCVSS 8.4EG 8.42025-08-21
VariCAD EN up to and including version 2010-2.05 is vulnerable to a stack-based buffer overflow when parsing .dwb drawing files. The application fails to properly validate the length of input data embedded in the file, allowing a crafted .…
- CVE-2010-20108HIGHCVSS 8.4EG 8.42025-08-21
FTPPad <= 1.2.0 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long directory …
- CVE-2009-20004HIGHCVSS 8.4EG 8.42025-08-21
gAlan 0.2.1, a modular audio processing environment for Windows, is vulnerable to a stack-based buffer overflow when parsing .galan files. The application fails to properly validate the length of input data, allowing a specially crafted fi…
- CVE-2009-20003HIGHCVSS 8.4EG 8.42025-08-21
Xenorate versions up to and including 2.50, a Windows-based multimedia player, is vulnerable to a stack-based buffer overflow when processing .xpl playlist files. The application fails to properly validate the length of input data, allowin…
- CVE-2009-20002HIGHCVSS 8.4EG 8.42025-08-21
Millenium MP3 Studio versions up to and including 2.0 is vulnerable to a stack-based buffer overflow when parsing .pls playlist files. The application fails to properly validate the length of the File1 field within the playlist, allowing a…
- CVE-2010-20111HIGHCVSS 8.4EG 8.42025-08-21
Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate in…
- CVE-2010-10015HIGHCVSS 8.4EG 8.42025-08-21
AOL versions up to and including 9.5 includes an ActiveX control (Phobos.dll) that exposes a method called Import() via the Phobos.Playlist COM object. This method is vulnerable to a stack-based buffer overflow when provided with an excess…
- CVE-2010-20010HIGHCVSS 8.4EG 8.42025-08-20
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Ha…
- CVE-2011-10027HIGHCVSS 8.4EG 8.42025-08-20
AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of…
- CVE-2011-10024HIGHCVSS 8.4EG 8.42025-08-20
MJM Core Player (likely now referred to as MJM Player) 2011 is vulnerable to a stack-based buffer overflow when parsing specially crafted .s3m music files. The vulnerability arises from improper bounds checking in the file parser, allowing…
- CVE-2011-10023HIGHCVSS 8.4EG 8.42025-08-20
MJM QuickPlayer (also known as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an …
- CVE-2011-10021HIGHCVSS 8.4EG 8.42025-08-20
Magix Musik Maker 16 is vulnerable to a stack-based buffer overflow due to improper handling of .mmm arrangement files. The vulnerability arises from an unsafe strcpy() operation that fails to validate input length, allowing attackers to o…
- CVE-2010-20042HIGHCVSS 8.4EG 8.42025-08-20
Xion Audio Player versions 1.0.126 and prior are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Except…
- CVE-2012-10057HIGHCVSS 8.4EG 8.42025-08-13
Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, a…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →