CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,566 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 16 of 72
- CVE-2022-26873HIGHCVSS 8.2EG 8.22022-09-20
A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Vi…
- CVE-2022-27646HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authenti…
- CVE-2022-27648HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or ope…
- CVE-2022-27783HIGHCVSS 7.8EG 7.82022-05-06
Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the c…
- CVE-2022-27784HIGHCVSS 7.8EG 7.82022-05-06
Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the c…
- CVE-2022-27791HIGHCVSS 7.8EG 7.82022-05-11
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbi…
- CVE-2022-2825CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
- CVE-2022-28304HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-28305HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-28306HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-28315HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a maliciou…
- CVE-2022-28750CRITICALCVSS 7.5EG 9.82022-08-11
Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions …
- CVE-2022-28772HIGHCVSS 7.5EG 7.52022-04-12
By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22…
- CVE-2022-2895HIGHCVSS 7.8EG 7.82022-08-31
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file.
- CVE-2022-2896HIGHCVSS 7.8EG 7.82022-08-31
Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.
- CVE-2022-29496CRITICALCVSS 9.8EG 9.82022-06-17
A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigge…
- CVE-2022-2970CRITICALCVSS 10.0EG 10.02022-09-23
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute…
- CVE-2022-2972CRITICALCVSS 10.0EG 10.02022-09-23
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execut…
- CVE-2022-30306HIGHCVSS 6.6EG 8.82023-02-16
A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via …
- CVE-2022-3085HIGHCVSS 7.8EG 7.82023-01-19
Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code.
- CVE-2022-31226HIGHCVSS 7.1EG 7.82022-09-12
Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the…
- CVE-2022-3159HIGHCVSS 7.8EG 7.82023-01-13
The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
- CVE-2022-3228MEDIUMCVSS 6.5EG 6.52022-10-28
Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM100 Communications Module Firmware versions v5.0.155 and prio…
- CVE-2022-32454CRITICALCVSS 9.8EG 9.82022-10-25
A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a mal…
- CVE-2022-32493HIGHCVSS 6.0EG 7.82022-10-12
Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
- CVE-2022-32502MEDIUMCVSS 6.3EG 6.32024-05-14
An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 befor…
- CVE-2022-3296HIGHCVSS 7.8EG 7.82022-09-25
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- CVE-2022-33213HIGHCVSS 7.5EG 8.82023-03-10
Memory corruption in modem due to buffer overflow while processing a PPP packet
- CVE-2022-3324HIGHCVSS 7.8EG 7.82022-09-27
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- CVE-2022-33260HIGHCVSS 5.9EG 7.82023-03-10
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
- CVE-2022-33264HIGHCVSS 7.9EG 7.92023-06-06
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- CVE-2022-33279CRITICALCVSS 9.8EG 9.82023-02-12
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
- CVE-2022-3385CRITICALCVSS 9.8EG 9.82022-10-27
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
- CVE-2022-3386CRITICALCVSS 9.8EG 9.82022-10-27
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
- CVE-2022-33871HIGHCVSS 6.6EG 7.22023-02-16
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `e…
- CVE-2022-3409HIGHCVSS 8.2EG 8.22022-10-27
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled t…
- CVE-2022-34401HIGHCVSS 7.5EG 7.52023-01-18
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary c…
- CVE-2022-34403HIGHCVSS 7.5EG 8.82023-02-01
Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution…
- CVE-2022-34667MEDIUMCVSS 4.4EG 4.42022-11-19
NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrup…
- CVE-2022-34884HIGHCVSS 7.2EG 7.22023-01-30
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
- CVE-2022-35299CRITICALCVSS 9.8EG 9.82022-10-11
SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.
- CVE-2022-35690CRITICALCVSS 9.8EG 9.82022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
- CVE-2022-35710CRITICALCVSS 9.8EG 9.82022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
- CVE-2022-35867MEDIUMCVSS 6.7EG 6.72022-08-03
This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerabilit…
- CVE-2022-36063HIGHCVSS 7.6EG 7.62022-10-10
Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC…
- CVE-2022-36337HIGHCVSS 8.2EG 8.22022-11-23
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overfl…
- CVE-2022-37398HIGHCVSS 7.1EG 8.82022-08-05
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and bel…
- CVE-2022-38450HIGHCVSS 7.8EG 7.82022-10-14
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
- CVE-2022-38672MEDIUMCVSS 5.5EG 5.52022-10-14
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38749MEDIUMCVSS 6.5EG 6.52022-09-05
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →