CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 42 of 79
- CVE-2023-48262HIGHCVSS 8.1EG 8.12024-01-10
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.
- CVE-2022-41981HIGHCVSS 8.1EG 8.12022-12-22
A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to out of bounds read and write on the process stack, which can lead to arbitrary code execu…
- CVE-2021-3057HIGHCVSS 8.1EG 8.12021-10-13
A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue …
- CVE-2020-25856HIGHCVSS 8.1EG 8.12021-02-03
The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operation, resulting in a stack buffer overflow…
- CVE-2020-25855HIGHCVSS 8.1EG 8.12021-02-03
The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for a memcpy() operation, resulting in a stack buffer overflow which ca…
- CVE-2020-25854HIGHCVSS 8.1EG 8.12021-02-03
The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, rt_arc4_crypt_veneer() or _AES_UnWRAP_ven…
- CVE-2020-25844HIGHCVSS 8.1EG 8.12020-12-31
The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.
- CVE-2020-7845HIGHCVSS 8.1EG 8.12020-12-27
Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.
- CVE-2025-40596HIGHCVSS 7.3EG 8.12025-07-23
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
- CVE-2022-1669HIGHCVSS 6.8EG 8.12022-05-24
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in th…
- CVE-2021-21540HIGHCVSS 5.9EG 8.12021-04-30
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to overwrite configuration information by injecting arbitrarily large p…
- CVE-2026-15781HIGHCVSS 8.0EG 8.02026-10-08
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
- CVE-2026-69503HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69301HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68838HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68834HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69412HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-68878HIGHCVSS 8.0EG 8.02026-09-08
Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-12222HIGHCVSS 8.0EG 8.02026-06-15
A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserve…
- CVE-2026-12221HIGHCVSS 8.0EG 8.02026-06-15
A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset resul…
- CVE-2026-12220HIGHCVSS 8.0EG 8.02026-06-15
A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the arg…
- CVE-2026-12218HIGHCVSS 8.0EG 8.02026-06-15
A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port res…
- CVE-2026-5295HIGHCVSS 8.0EG 8.02026-04-09
A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/pkcs7.c. When processing a CMS EnvelopedData message containing an OtherRecipientInfo (ORI) recipient, the function cop…
- CVE-2026-30814HIGHCVSS 8.0EG 8.02026-04-08
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file.…
- CVE-2026-5684HIGHCVSS 8.0EG 8.02026-04-06
A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based buff…
- CVE-2026-5683HIGHCVSS 8.0EG 8.02026-04-06
A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument page results in stack-based buffer overflow…
- CVE-2026-32708HIGHCVSS 8.0EG 8.02026-03-16
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented…
- CVE-2025-25679HIGHCVSS 8.0EG 8.02025-02-20
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
- CVE-2024-46435HIGHCVSS 8.0EG 8.02025-02-10
A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper i…
- CVE-2024-41592HIGHCVSS 8.0EG 8.02024-10-03
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
- CVE-2024-41590HIGHCVSS 8.0EG 8.02024-10-03
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.
- CVE-2024-41586HIGHCVSS 8.0EG 8.02024-10-03
A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.
- CVE-2024-46313HIGHCVSS 8.0EG 8.02024-09-30
TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.
- CVE-2024-23967HIGHCVSS 8.0EG 8.02024-09-28
Autel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of …
- CVE-2024-23959HIGHCVSS 8.0EG 8.02024-09-28
Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Aut…
- CVE-2024-23935HIGHCVSS 8.0EG 8.02024-09-28
Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must fir…
- CVE-2024-44859HIGHCVSS 8.0EG 8.02024-09-04
Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
- CVE-2024-37978HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37972HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37971HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37970HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-35578HIGHCVSS 8.0EG 8.02024-05-20
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
- CVE-2023-51628HIGHCVSS 8.0EG 8.02024-05-03
D-Link DCS-8300LHV2 ONVIF SetHostName Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DCS-8300LHV2 IP camer…
- CVE-2023-51627HIGHCVSS 8.0EG 8.02024-05-03
D-Link DCS-8300LHV2 ONVIF Duration Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DCS-8300LHV2 IP cameras.…
- CVE-2023-51613HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-X3260 prog.cgi SetDynamicDNSSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 r…
- CVE-2023-44431HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is…
- CVE-2023-41184HIGHCVSS 8.0EG 8.02024-05-03
TP-Link Tapo C210 ActiveCells Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Tapo C210 IP cameras. Althou…
- CVE-2023-27361HIGHCVSS 8.0EG 8.02024-05-03
NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authenti…
- CVE-2024-32303HIGHCVSS 8.0EG 8.02024-04-17
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32293HIGHCVSS 8.0EG 8.02024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →