CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 46 of 79
- CVE-2025-64469HIGHCVSS 7.8EG 7.82025-12-18
There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploit…
- CVE-2025-54526HIGHCVSS 7.8EG 7.82025-11-04
Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.
- CVE-2025-20737HIGHCVSS 7.8EG 7.82025-11-04
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- CVE-2025-47360HIGHCVSS 7.8EG 7.82025-11-04
Memory corruption while processing client message during device management.
- CVE-2025-10925HIGHCVSS 7.8EG 7.82025-10-29
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…
- CVE-2025-40843HIGHCVSS 7.8EG 7.82025-10-28
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which …
- CVE-2025-5555HIGHCVSS 7.8EG 7.82025-10-18
A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local acce…
- CVE-2025-62580HIGHCVSS 7.8EG 7.82025-10-16
ASDA-Soft Stack-based Buffer Overflow Vulnerability
- CVE-2025-62579HIGHCVSS 7.8EG 7.82025-10-16
ASDA-Soft Stack-based Buffer Overflow Vulnerability
- CVE-2025-54274HIGHCVSS 7.8EG 7.82025-10-14
Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac…
- CVE-2025-24052HIGHCVSS 7.8EG 7.82025-10-14
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed …
- CVE-2025-20718HIGHCVSS 7.8EG 7.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- CVE-2025-20717HIGHCVSS 7.8EG 7.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed fo…
- CVE-2025-20714HIGHCVSS 7.8EG 7.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed fo…
- CVE-2025-20713HIGHCVSS 7.8EG 7.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed fo…
- CVE-2025-61856HIGHCVSS 7.8EG 7.82025-10-10
A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), …
- CVE-2025-47347HIGHCVSS 7.8EG 7.82025-10-09
Memory corruption while processing control commands in the virtual memory management interface.
- CVE-2025-58776HIGHCVSS 7.8EG 7.82025-10-02
KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
- CVE-2025-58775HIGHCVSS 7.8EG 7.82025-10-02
KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
- CVE-2025-23339HIGHCVSS 7.8EG 7.82025-09-24
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability …
- CVE-2025-58319HIGHCVSS 7.8EG 7.82025-09-24
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
- CVE-2025-58317HIGHCVSS 7.8EG 7.82025-09-24
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
- CVE-2025-7979HIGHCVSS 7.8EG 7.82025-09-17
Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interac…
- CVE-2025-54916HIGHCVSS 7.8EG 7.82025-09-09
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2025-9300HIGHCVSS 7.8EG 7.82025-08-21
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The…
- CVE-2025-9175HIGHCVSS 7.8EG 7.82025-08-19
A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The e…
- CVE-2025-8962HIGHCVSS 7.8EG 7.82025-08-14
A vulnerability was found in code-projects Hostel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file hostel_manage.exe of the component Login Form. The manipulation of the argument uname leads to …
- CVE-2025-49564HIGHCVSS 7.8EG 7.82025-08-12
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-8846HIGHCVSS 7.8EG 7.82025-08-11
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has be…
- CVE-2025-8845HIGHCVSS 7.8EG 7.82025-08-11
A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host…
- CVE-2025-7032HIGHCVSS 7.8EG 7.82025-08-05
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage.…
- CVE-2025-23284HIGHCVSS 7.8EG 7.82025-08-02
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, information …
- CVE-2025-23283HIGHCVSS 7.8EG 7.82025-08-02
NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denia…
- CVE-2025-33092HIGHCVSS 7.8EG 7.82025-07-29
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
- CVE-2025-49528HIGHCVSS 7.8EG 7.82025-07-08
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-49527HIGHCVSS 7.8EG 7.82025-07-08
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-40741HIGHCVSS 7.8EG 7.82025-07-08
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted CFG files. This could allow an attacker to e…
- CVE-2025-6663HIGHCVSS 7.8EG 7.82025-07-07
GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is req…
- CVE-2025-6857HIGHCVSS 7.8EG 7.82025-06-29
A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to …
- CVE-2025-41388HIGHCVSS 7.8EG 7.82025-06-17
Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
- CVE-2025-47760HIGHCVSS 7.8EG 7.82025-05-19
V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
- CVE-2025-47759HIGHCVSS 7.8EG 7.82025-05-19
V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execu…
- CVE-2025-47758HIGHCVSS 7.8EG 7.82025-05-19
V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code exec…
- CVE-2025-30421HIGHCVSS 7.8EG 7.82025-05-15
There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitr…
- CVE-2025-1253HIGHCVSS 7.8EG 7.82025-05-08
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: fro…
- CVE-2025-46397HIGHCVSS 7.8EG 7.82025-04-23
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
- CVE-2025-30298HIGHCVSS 7.8EG 7.82025-04-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user int…
- CVE-2025-26688HIGHCVSS 7.8EG 7.82025-04-08
Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
- CVE-2025-27168HIGHCVSS 7.8EG 7.82025-03-11
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-24075HIGHCVSS 7.8EG 7.82025-03-11
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →