CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 40 of 79
- CVE-2011-10012HIGHCVSS 8.4EG 8.42025-08-13
NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perfor…
- CVE-2012-10051HIGHCVSS 8.4EG 8.42025-08-08
Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugin load list files. When a specially crafted load file is placed in the installation directory, the application fails to…
- CVE-2013-10036HIGHCVSS 8.4EG 8.42025-07-31
A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserNam…
- CVE-2014-125114HIGHCVSS 8.4EG 8.42025-07-25
A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placing a specially crafted Schedule.xml file in the i-Ftp application directory, a remote atta…
- CVE-2025-34124HIGHCVSS 8.4EG 8.42025-07-16
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in…
- CVE-2025-34123HIGHCVSS 8.4EG 8.42025-07-16
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, l…
- CVE-2019-16641HIGHCVSS 8.4EG 8.42024-07-16
An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1.
- CVE-2024-37984HIGHCVSS 8.4EG 8.42024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-36600HIGHCVSS 8.4EG 8.42024-06-14
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
- CVE-2024-35333HIGHCVSS 8.4EG 8.42024-05-29
A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vuln…
- CVE-2024-21474HIGHCVSS 8.4EG 8.42024-05-06
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
- CVE-2024-25391HIGHCVSS 8.4EG 8.42024-03-27
A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.
- CVE-2024-28582HIGHCVSS 8.4EG 8.42024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.
- CVE-2024-28581HIGHCVSS 8.4EG 8.42024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.
- CVE-2024-28580HIGHCVSS 8.4EG 8.42024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
- CVE-2024-28578HIGHCVSS 8.4EG 8.42024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
- CVE-2024-28566HIGHCVSS 8.4EG 8.42024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.
- CVE-2023-43549HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption while processing TPC target power table in FTM TPC.
- CVE-2023-28538HIGHCVSS 8.4EG 8.42023-09-05
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- CVE-2023-21632HIGHCVSS 8.4EG 8.42023-06-06
Memory corruption in Automotive GPU while querying a gsl memory node.
- CVE-2022-40517HIGHCVSS 8.4EG 8.42023-01-09
Memory corruption in core due to stack-based buffer overflow
- CVE-2022-40516HIGHCVSS 8.4EG 8.42023-01-09
Memory corruption in Core due to stack-based buffer overflow.
- CVE-1999-0029HIGHCVSS 8.4EG 8.41997-07-16
root privileges via buffer overflow in ordist command on SGI IRIX systems.
- CVE-2026-10535HIGHCVSS 7.8EG 8.42026-07-30
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
- CVE-2019-25336HIGHCVSS 7.8EG 8.42026-02-12
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encod…
- CVE-2026-24882HIGHCVSS 7.8EG 8.42026-01-27
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
- CVE-2021-44703HIGHCVSS 7.8EG 8.42022-01-14
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbi…
- CVE-2021-33549HIGHCVSS 7.2EG 8.42021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.
- CVE-2026-84351HIGHCVSS 8.3EG 8.32026-09-01
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever…
- CVE-2026-62349HIGHCVSS 8.3EG 8.32026-07-15
TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \…
- CVE-2026-10898HIGHCVSS 8.3EG 8.32026-06-04
Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-41927HIGHCVSS 8.3EG 8.32026-05-04
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sen…
- CVE-2025-26336HIGHCVSS 8.3EG 8.32025-03-21
Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a …
- CVE-2023-37296HIGHCVSS 8.3EG 8.32024-01-09
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or avai…
- CVE-2023-40465HIGHCVSS 8.3EG 8.32023-12-04
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
- CVE-2020-10064HIGHCVSS 8.3EG 8.32021-05-25
Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject…
- CVE-2019-17094HIGHCVSS 8.3EG 8.32020-01-27
A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware versio…
- CVE-2018-20247HIGHCVSS 7.8EG 8.32018-12-24
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack ove…
- CVE-2014-0782HIGHCVSS v2 8.3EG 8.32014-05-16
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Ex…
- CVE-2014-0784HIGHCVSS v2 8.3EG 8.32014-03-14
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
- CVE-2026-57161HIGHCVSS 8.2EG 8.22026-09-04
PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when processing Service-Route headers in a registration response (update_service_route() in pjs…
- CVE-2026-17494HIGHCVSS 8.2EG 8.22026-08-19
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, all…
- CVE-2026-17093HIGHCVSS 8.2EG 8.22026-08-19
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmw…
- CVE-2026-19234HIGHCVSS 8.2EG 8.22026-08-19
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor…
- CVE-2026-14679HIGHCVSS 8.2EG 8.22026-08-13
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, an…
- CVE-2026-49759HIGHCVSS 8.2EG 8.22026-06-10
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/com…
- CVE-2026-9669HIGHCVSS 8.2EG 8.22026-06-08
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal s…
- CVE-2026-29972HIGHCVSS 8.2EG 8.22026-05-08
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server r…
- CVE-2025-15555HIGHCVSS 8.2EG 8.22026-02-04
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LE…
- CVE-2025-4425HIGHCVSS 8.2EG 8.22025-07-30
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/pr…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →