CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 53 of 79
- CVE-2024-35579HIGHCVSS 7.7EG 7.72024-05-20
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.
- CVE-2024-34217HIGHCVSS 7.7EG 7.72024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.
- CVE-2026-42804HIGHCVSS 7.6EG 7.62026-09-10
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem in…
- CVE-2026-6687HIGHCVSS 7.6EG 7.62026-07-01
FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CV…
- CVE-2025-59251HIGHCVSS 7.6EG 7.62025-09-24
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-6137HIGHCVSS 7.6EG 7.62024-09-13
BT: Classic: SDP OOB access in get_att_search_list
- CVE-2024-41630HIGHCVSS 7.6EG 7.62024-07-31
Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
- CVE-2023-3725HIGHCVSS 7.6EG 7.62023-10-06
Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
- CVE-2022-36063HIGHCVSS 7.6EG 7.62022-10-10
Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC…
- CVE-2026-102165HIGHCVSS 7.5EG 7.52026-10-06
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an u…
- CVE-2026-102167HIGHCVSS 7.5EG 7.52026-10-06
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Explo…
- CVE-2026-63292HIGHCVSS 7.5EG 7.52026-10-01
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request w…
- CVE-2026-92870HIGHCVSS 7.5EG 7.52026-09-30
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
- CVE-2026-95104HIGHCVSS 7.5EG 7.52026-09-28
Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.
- CVE-2026-100908HIGHCVSS 7.5EG 7.52026-09-28
A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has b…
- CVE-2026-88388HIGHCVSS 7.5EG 7.52026-09-24
Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches js…
- CVE-2026-88406HIGHCVSS 7.5EG 7.52026-09-21
FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted inp…
- CVE-2026-81944HIGHCVSS 7.5EG 7.52026-09-18
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer al…
- CVE-2026-33963HIGHCVSS 7.5EG 7.52026-09-14
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of servic…
- CVE-2026-90779HIGHCVSS 7.5EG 7.52026-09-13
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to co…
- CVE-2026-86093HIGHCVSS 7.5EG 7.52026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that impro…
- CVE-2026-88289HIGHCVSS 7.5EG 7.52026-09-10
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the…
- CVE-2026-88287HIGHCVSS 7.5EG 7.52026-09-10
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
- CVE-2026-77101HIGHCVSS 7.5EG 7.52026-09-08
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- CVE-2026-67560HIGHCVSS 7.5EG 7.52026-08-27
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could c…
- CVE-2026-68863HIGHCVSS 7.5EG 7.52026-08-26
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2026-75368HIGHCVSS 7.5EG 7.52026-08-24
A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.
- CVE-2026-76879HIGHCVSS 7.5EG 7.52026-08-19
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-45798HIGHCVSS 7.5EG 7.52026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field i…
- CVE-2026-73522HIGHCVSS 7.5EG 7.52026-08-17
COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CA…
- CVE-2026-71979HIGHCVSS 7.5EG 7.52026-08-17
INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML w…
- CVE-2026-20345HIGHCVSS 7.5EG 7.52026-08-07
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulner…
- CVE-2026-71265HIGHCVSS 7.5EG 7.52026-08-05
Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length chec…
- CVE-2026-67866HIGHCVSS 7.5EG 7.52026-08-05
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMo…
- CVE-2026-15722HIGHCVSS 7.5EG 7.52026-07-31
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bou…
- CVE-2026-43832HIGHCVSS 7.5EG 7.52026-07-31
Full details and mitigation steps are currently restricted and will be published at a later date.
- CVE-2026-43831HIGHCVSS 7.5EG 7.52026-07-31
Full details and mitigation steps are currently restricted and will be published at a later date.
- CVE-2026-43829HIGHCVSS 7.5EG 7.52026-07-31
Full details and mitigation steps are currently restricted and will be published at a later date.
- CVE-2026-11771HIGHCVSS 7.5EG 7.52026-07-30
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
- CVE-2026-58181HIGHCVSS 7.5EG 7.52026-07-29
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. U…
- CVE-2026-58180HIGHCVSS 7.5EG 7.52026-07-29
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomm…
- CVE-2026-50039HIGHCVSS 7.5EG 7.52026-07-23
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.
- CVE-2026-56455HIGHCVSS 7.5EG 7.52026-07-16
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memo…
- CVE-2026-48863HIGHCVSS 7.5EG 7.52026-07-16
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed…
- CVE-2026-38752HIGHCVSS 7.5EG 7.52026-07-15
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
- CVE-2026-47477HIGHCVSS 7.5EG 7.52026-07-14
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2026-50527HIGHCVSS 7.5EG 7.52026-07-14
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-50411HIGHCVSS 7.5EG 7.52026-07-14
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- CVE-2026-50355HIGHCVSS 7.5EG 7.52026-07-14
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- CVE-2026-50368HIGHCVSS 7.5EG 7.52026-07-14
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →