CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 5 of 79
- CVE-2026-10534CRITICALCVSS 9.8EG 9.82026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
- CVE-2026-62878CRITICALCVSS 9.8EG 9.82026-08-11
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- CVE-2026-71267CRITICALCVSS 9.8EG 9.82026-08-05
microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) i…
- CVE-2026-61486CRITICALCVSS 9.8EG 9.82026-08-05
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are …
- CVE-2026-45538CRITICALCVSS 9.8EG 9.82026-08-04
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routin…
- CVE-2026-49435CRITICALCVSS 9.8EG 9.82026-08-04
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
- CVE-2017-20242CRITICALCVSS 9.8EG 9.82026-08-04
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
- CVE-2026-18589CRITICALCVSS 9.8EG 9.82026-08-03
A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed …
- CVE-2026-18588CRITICALCVSS 9.8EG 9.82026-08-03
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the atta…
- CVE-2026-67822CRITICALCVSS 9.8EG 9.82026-07-31
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer with…
- CVE-2026-58179CRITICALCVSS 9.8EG 9.82026-07-29
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users …
- CVE-2026-59144CRITICALCVSS 9.8EG 9.82026-07-21
Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of …
- CVE-2024-51311CRITICALCVSS 9.8EG 9.82026-07-20
The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
- CVE-2024-51312CRITICALCVSS 9.8EG 9.82026-07-20
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.
- CVE-2024-51313CRITICALCVSS 9.8EG 9.82026-07-20
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
- CVE-2024-51314CRITICALCVSS 9.8EG 9.82026-07-20
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.
- CVE-2024-51315CRITICALCVSS 9.8EG 9.82026-07-20
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
- CVE-2026-15701CRITICALCVSS 9.8EG 9.82026-07-14
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based b…
- CVE-2026-51807CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_len…
- CVE-2026-10666CRITICALCVSS 9.8EG 9.82026-07-12
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end …
- CVE-2026-57878CRITICALCVSS 9.8EG 9.82026-06-26
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a…
- CVE-2026-57879CRITICALCVSS 9.8EG 9.82026-06-26
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication da…
- CVE-2026-57880CRITICALCVSS 9.8EG 9.82026-06-26
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication field…
- CVE-2026-57881CRITICALCVSS 9.8EG 9.82026-06-26
An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remot…
- CVE-2026-51843CRITICALCVSS 9.8EG 9.82026-06-19
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
- CVE-2026-51844CRITICALCVSS 9.8EG 9.82026-06-19
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.
- CVE-2026-51845CRITICALCVSS 9.8EG 9.82026-06-19
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.
- CVE-2026-51846CRITICALCVSS 9.8EG 9.82026-06-19
In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.
- CVE-2026-44815CRITICALCVSS 9.8EG 9.82026-06-09
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-27671CRITICALCVSS 9.8EG 9.82026-06-09
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management,…
- CVE-2026-11499CRITICALCVSS 9.8EG 9.82026-06-08
A vulnerability was determined in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer over…
- CVE-2018-25427CRITICALCVSS 9.8EG 9.82026-06-01
Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 by…
- CVE-2026-10187CRITICALCVSS 9.8EG 9.82026-05-31
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument Key…
- CVE-2026-10064CRITICALCVSS 9.8EG 9.82026-05-29
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. I…
- CVE-2026-10063CRITICALCVSS 9.8EG 9.82026-05-29
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be pe…
- CVE-2026-10062CRITICALCVSS 9.8EG 9.82026-05-29
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overfl…
- CVE-2026-8363CRITICALCVSS 9.8EG 9.82026-05-27
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
- CVE-2026-8362CRITICALCVSS 9.8EG 9.82026-05-27
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
- CVE-2026-8836CRITICALCVSS 9.8EG 9.82026-05-18
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameter…
- CVE-2026-32661CRITICALCVSS 9.8EG 9.82026-05-13
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be exec…
- CVE-2026-42854CRITICALCVSS 9.8EG 9.82026-05-12
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack…
- CVE-2026-41089CRITICALCVSS 9.8EG 9.82026-05-12
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- CVE-2026-6665CRITICALCVSS 9.8EG 9.82026-05-09
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can…
- CVE-2026-41509CRITICALCVSS 9.8EG 9.82026-05-08
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This…
- CVE-2026-7834CRITICALCVSS 9.8EG 9.82026-05-05
A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be la…
- CVE-2026-37539CRITICALCVSS 9.8EG 9.82026-05-01
Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arb…
- CVE-2026-42482CRITICALCVSS 9.8EG 9.82026-05-01
A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or…
- CVE-2026-7546CRITICALCVSS 9.8EG 9.82026-05-01
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow.…
- CVE-2026-33447CRITICALCVSS 9.8EG 9.82026-04-30
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably…
- CVE-2026-1951CRITICALCVSS 9.8EG 9.82026-04-24
Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →