CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,566 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 20 of 72
- CVE-2023-28393HIGHCVSS 5.6EG 8.82023-09-25
A stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file…
- CVE-2023-28538HIGHCVSS 8.4EG 8.42023-09-05
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- CVE-2023-28703HIGHCVSS 7.2EG 7.22023-06-02
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to exec…
- CVE-2023-28728HIGHCVSS 7.8EG 7.82023-07-21
A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.
- CVE-2023-28760HIGHCVSS 7.5EG 7.52025-10-02
TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker obtains the ability to modify files.db, and that can be used …
- CVE-2023-29182MEDIUMCVSS 6.4EG 6.42023-08-17
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack prote…
- CVE-2023-2923MEDIUMCVSS 6.3EG 6.32023-05-27
A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched r…
- CVE-2023-29284HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2023-29503HIGHCVSS 7.8EG 7.82023-06-06
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code…
- CVE-2023-29583HIGHCVSS 5.5EG 7.82023-04-24
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone…
- CVE-2023-3043CRITICALCVSS 9.6EG 9.62024-01-09
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, a…
- CVE-2023-30702MEDIUMCVSS 6.7EG 6.72023-08-10
Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows lo…
- CVE-2023-30733HIGHCVSS 7.8EG 7.82023-10-04
Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.
- CVE-2023-30900HIGHCVSS 7.8EG 7.82023-10-10
A vulnerability has been identified in Xpedition Layout Browser (All versions < VX.2.14). Affected application contains a stack overflow vulnerability when parsing a PCB file. An attacker can leverage this vulnerability to execute code in …
- CVE-2023-31024CRITICALCVSS 9.0EG 9.02024-01-12
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to …
- CVE-2023-31029CRITICALCVSS 9.3EG 9.32024-01-12
NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this…
- CVE-2023-31030CRITICALCVSS 9.3EG 9.32024-01-12
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitra…
- CVE-2023-31272HIGHCVSS 8.8EG 8.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigg…
- CVE-2023-31419HIGHCVSS 6.5EG 7.92023-10-26
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
- CVE-2023-3195MEDIUMCVSS 5.5EG 5.52023-06-16
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of se…
- CVE-2023-32136HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 webproc var:menu Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authenti…
- CVE-2023-32139HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 webproc Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is…
- CVE-2023-32140HIGHCVSS 7.5EG 7.52024-05-03
D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Auth…
- CVE-2023-32141HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 webproc WEB_DisplayPage Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. A…
- CVE-2023-32142HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 webproc var:page Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authenti…
- CVE-2023-32144HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 webproc COMM_MakeCustomMsg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers…
- CVE-2023-32146HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 Multiple Parameters Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authe…
- CVE-2023-32149HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-2640 prog.cgi Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers.…
- CVE-2023-32971LOWCVSS 3.8EG 3.82023-10-06
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have…
- CVE-2023-32972LOWCVSS 3.8EG 3.82023-10-06
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have…
- CVE-2023-32973LOWCVSS 3.8EG 3.82023-10-13
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have…
- CVE-2023-33028CRITICALCVSS 9.8EG 9.82023-10-03
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
- CVE-2023-33218CRITICALCVSS 9.1EG 9.12023-12-15
The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device.
- CVE-2023-33219CRITICALCVSS 9.1EG 9.12023-12-15
The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the…
- CVE-2023-33220CRITICALCVSS 9.1EG 9.12023-12-15
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on th…
- CVE-2023-33222MEDIUMCVSS 6.8EG 6.82023-12-15
When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could l…
- CVE-2023-33308CRITICALCVSS 9.8EG 9.82023-07-26
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute …
- CVE-2023-34095CRITICALCVSS 9.8EG 9.82023-06-14
cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf…
- CVE-2023-34285HIGHCVSS 8.8EG 8.82024-05-03
NETGEAR RAX30 cmsCli_authenticate Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentic…
- CVE-2023-34287HIGHCVSS 7.8EG 7.82024-05-03
Ashlar-Vellum Cobalt CO File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction …
- CVE-2023-34302HIGHCVSS 7.8EG 7.82024-05-03
Ashlar-Vellum Cobalt CO File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction …
- CVE-2023-34306HIGHCVSS 8.8EG 8.82024-05-03
Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interac…
- CVE-2023-34365CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to tr…
- CVE-2023-34426CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request …
- CVE-2023-34552HIGHCVSS 8.8EG 8.82023-08-01
In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol can allow an unauthenticated attacker present on the same local network as the ca…
- CVE-2023-35012MEDIUMCVSS 6.7EG 6.72023-07-17
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with SYSADM privileges could overflow t…
- CVE-2023-35055HIGHCVSS 8.8EG 8.82023-10-11
A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerabili…
- CVE-2023-35056HIGHCVSS 8.8EG 8.82023-10-11
A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerabili…
- CVE-2023-35127HIGHCVSS 7.8EG 7.82023-11-22
Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.
- CVE-2023-35322HIGHCVSS 8.8EG 8.82023-07-11
Windows Deployment Services Remote Code Execution Vulnerability
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →