CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 55 of 79
- CVE-2026-41681HIGHCVSS 7.5EG 7.52026-04-24
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes…
- CVE-2026-40170HIGHCVSS 7.5EG 7.52026-04-16
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog …
- CVE-2026-30364HIGHCVSS 7.5EG 7.52026-04-15
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
- CVE-2026-32203HIGHCVSS 7.5EG 7.52026-04-14
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
- CVE-2026-4156HIGHCVSS 7.5EG 7.52026-04-11
ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex EV charge…
- CVE-2025-50671HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively lon…
- CVE-2025-50664HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters n…
- CVE-2025-50663HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
- CVE-2025-50662HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
- CVE-2025-50661HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parame…
- CVE-2025-50660HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
- CVE-2025-50659HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
- CVE-2025-50657HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
- CVE-2025-50655HIGHCVSS 7.5EG 7.52026-04-08
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
- CVE-2026-25833HIGHCVSS 7.5EG 7.52026-04-01
Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
- CVE-2026-33554HIGHCVSS 7.5EG 7.52026-03-24
ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large …
- CVE-2026-33307HIGHCVSS 7.5EG 7.52026-03-24
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t x509[]` ar…
- CVE-2026-33250HIGHCVSS 7.5EG 7.52026-03-24
Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A mali…
- CVE-2025-70244HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.
- CVE-2025-70251HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.
- CVE-2025-70249HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.
- CVE-2025-70247HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.
- CVE-2025-70246HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.
- CVE-2025-70242HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
- CVE-2025-70227HIGHCVSS 7.5EG 7.52026-03-10
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
- CVE-2025-70250HIGHCVSS 7.5EG 7.52026-03-09
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.
- CVE-2025-70243HIGHCVSS 7.5EG 7.52026-03-09
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.
- CVE-2025-70238HIGHCVSS 7.5EG 7.52026-03-09
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.
- CVE-2026-29068HIGHCVSS 7.5EG 7.52026-03-06
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided fram…
- CVE-2025-69765HIGHCVSS 7.5EG 7.52026-03-03
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.
- CVE-2025-70252HIGHCVSS 7.5EG 7.52026-03-02
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,w…
- CVE-2025-69700HIGHCVSS 7.5EG 7.52026-02-23
Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.
- CVE-2019-25363HIGHCVSS 7.5EG 7.52026-02-18
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'L…
- CVE-2026-26269HIGHCVSS 7.5EG 7.52026-02-13
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans f…
- CVE-2019-25341HIGHCVSS 7.5EG 7.52026-02-12
iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98-character buffer into the Domain Name f…
- CVE-2019-25340HIGHCVSS 7.5EG 7.52026-02-12
SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated…
- CVE-2019-25339HIGHCVSS 7.5EG 7.52026-02-12
GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated characters into the password field to trigg…
- CVE-2019-25330HIGHCVSS 7.5EG 7.52026-02-12
SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 38…
- CVE-2019-25329HIGHCVSS 7.5EG 7.52026-02-12
FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwriting Structured Exception Handler (SEH) with malicious input. Attackers can generate a payload of 4108 'A' characters fo…
- CVE-2019-25328HIGHCVSS 7.5EG 7.52026-02-12
XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registrat…
- CVE-2025-67432HIGHCVSS 7.5EG 7.52026-02-12
A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2020-37198HIGHCVSS 7.5EG 7.52026-02-11
Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into…
- CVE-2020-37182HIGHCVSS 7.5EG 7.52026-02-11
Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length checking to over…
- CVE-2020-37177HIGHCVSS 7.5EG 7.52026-02-11
BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte pa…
- CVE-2020-37122HIGHCVSS 7.5EG 7.52026-02-07
SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a…
- CVE-2020-37136HIGHCVSS 7.5EG 7.52026-02-05
ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the appl…
- CVE-2020-37133HIGHCVSS 7.5EG 7.52026-02-05
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Hos…
- CVE-2025-63658HIGHCVSS 7.5EG 7.52026-01-29
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
- CVE-2025-70648HIGHCVSS 7.5EG 7.52026-01-21
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
- CVE-2025-70646HIGHCVSS 7.5EG 7.52026-01-21
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →