CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 44 of 79
- CVE-2026-77658HIGHCVSS 7.8EG 7.82026-08-26
A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus…
- CVE-2026-48417HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o…
- CVE-2026-16945HIGHCVSS 7.8EG 7.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
- CVE-2026-18303HIGHCVSS 7.8EG 7.82026-08-20
GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vul…
- CVE-2026-18297HIGHCVSS 7.8EG 7.82026-08-20
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploi…
- CVE-2026-75142HIGHCVSS 7.8EG 7.82026-08-19
FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted inpu…
- CVE-2026-54758HIGHCVSS 7.8EG 7.82026-08-17
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and ) into the fixed-si…
- CVE-2026-19003HIGHCVSS 7.8EG 7.82026-08-12
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculat…
- CVE-2026-68817HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-66807HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-64919HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-64912HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-64907HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-63527HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-63526HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-62768HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-70346HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-70344HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-68816HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68795HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-62877HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-62755HIGHCVSS 7.8EG 7.82026-08-11
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-59086HIGHCVSS 7.8EG 7.82026-08-11
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one o…
- CVE-2026-21068HIGHCVSS 7.8EG 7.82026-08-10
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
- CVE-2026-71266HIGHCVSS 7.8EG 7.82026-08-05
tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplic…
- CVE-2026-10710HIGHCVSS 7.8EG 7.82026-08-04
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the conte…
- CVE-2026-10709HIGHCVSS 7.8EG 7.82026-08-04
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary…
- CVE-2026-5056HIGHCVSS 7.8EG 7.82026-07-29
GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to ex…
- CVE-2026-48389HIGHCVSS 7.8EG 7.82026-07-20
DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t…
- CVE-2026-47971HIGHCVSS 7.8EG 7.82026-07-14
Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma…
- CVE-2026-57091HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-55134HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55038HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55055HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55141HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-50501HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
- CVE-2026-50387HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
- CVE-2026-50400HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-50412HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-50318HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-49789HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-55899HIGHCVSS 7.8EG 7.82026-07-14
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-49033HIGHCVSS 7.8EG 7.82026-07-07
The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.
- CVE-2026-14789HIGHCVSS 7.8EG 7.82026-07-06
A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in st…
- CVE-2026-14606HIGHCVSS 7.8EG 7.82026-07-03
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a …
- CVE-2026-14605HIGHCVSS 7.8EG 7.82026-07-03
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-ba…
- CVE-2026-11979HIGHCVSS 7.8EG 7.82026-06-29
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplyin…
- CVE-2026-47959HIGHCVSS 7.8EG 7.82026-06-09
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…
- CVE-2026-34695HIGHCVSS 7.8EG 7.82026-06-09
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inter…
- CVE-2026-34697HIGHCVSS 7.8EG 7.82026-06-09
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inter…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →