CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 43 of 79
- CVE-2024-32285HIGHCVSS 8.0EG 8.02024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
- CVE-2024-32310HIGHCVSS 8.0EG 8.02024-04-17
Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.
- CVE-2024-28925HIGHCVSS 8.0EG 8.02024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-26180HIGHCVSS 8.0EG 8.02024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-30634HIGHCVSS 8.0EG 8.02024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.
- CVE-2024-30626HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.
- CVE-2024-30625HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.
- CVE-2024-30601HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
- CVE-2024-30600HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
- CVE-2024-30607HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
- CVE-2024-30606HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.
- CVE-2024-30592HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.
- CVE-2024-30583HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.
- CVE-2023-51147HIGHCVSS 8.0EG 8.02024-03-26
Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.
- CVE-2023-51146HIGHCVSS 8.0EG 8.02024-03-26
Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.
- CVE-2023-51148HIGHCVSS 8.0EG 8.02024-03-26
An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.
- CVE-2024-25756HIGHCVSS 8.0EG 8.02024-02-22
A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.
- CVE-2023-24334HIGHCVSS 8.0EG 8.02024-02-21
A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.
- CVE-2023-6749HIGHCVSS 8.0EG 8.02024-02-18
Unchecked length coming from user input in settings shell
- CVE-2023-35634HIGHCVSS 8.0EG 8.02023-12-12
Windows Bluetooth Driver Remote Code Execution Vulnerability
- CVE-2022-24973HIGHCVSS 8.0EG 8.02023-03-28
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The spec…
- CVE-2022-0650HIGHCVSS 8.0EG 8.02023-03-28
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The spec…
- CVE-2023-23780HIGHCVSS 8.0EG 8.02023-02-16
A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP req…
- CVE-2021-44158HIGHCVSS 8.0EG 8.02022-01-03
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrup…
- CVE-2021-22673HIGHCVSS 8.0EG 8.02021-05-07
The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 a…
- CVE-2021-27246HIGHCVSS 8.0EG 8.02021-04-14
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists wit…
- CVE-2020-8860HIGHCVSS 8.0EG 8.02020-02-22
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this…
- CVE-2026-86140HIGHCVSS 7.8EG 8.02026-09-05
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
- CVE-2023-40478HIGHCVSS 6.8EG 8.02024-05-03
NETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although au…
- CVE-2023-23781HIGHCVSS 6.4EG 8.02023-02-16
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via sp…
- CVE-2025-20618HIGHCVSS 7.9EG 7.92025-05-13
Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-33264HIGHCVSS 7.9EG 7.92023-06-06
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- CVE-2023-31419HIGHCVSS 6.5EG 7.92023-10-26
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
- CVE-2026-47593HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of pri…
- CVE-2026-83962HIGHCVSS 7.8EG 7.82026-09-22
Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o…
- CVE-2026-75676HIGHCVSS 7.8EG 7.82026-09-22
Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- CVE-2026-86054HIGHCVSS 7.8EG 7.82026-09-22
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDir=…
- CVE-2026-19477HIGHCVSS 7.8EG 7.82026-09-17
There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library fo…
- CVE-2026-88047HIGHCVSS 7.8EG 7.82026-09-10
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whites…
- CVE-2026-83990HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2026-81953HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81388HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81396HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-69290HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
- CVE-2026-69508HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- CVE-2026-69467HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2026-69277HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
- CVE-2026-71337HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- CVE-2026-69391HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73600HIGHCVSS 7.8EG 7.82026-09-03
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information …
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →