CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 48 of 72
- CVE-2025-44883CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.
- CVE-2025-44884CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.
- CVE-2025-44885CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.
- CVE-2025-44886CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.
- CVE-2025-44887CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.
- CVE-2025-44888CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.
- CVE-2025-44890CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.
- CVE-2025-44891CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.
- CVE-2025-44892MEDIUMCVSS 6.5EG 6.52025-05-21
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.
- CVE-2025-44893CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.
- CVE-2025-44894CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.
- CVE-2025-44895MEDIUMCVSS 6.5EG 6.52025-05-21
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.
- CVE-2025-44896CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.
- CVE-2025-44897CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.
- CVE-2025-44898CRITICALCVSS 9.8EG 9.82025-05-20
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.
- CVE-2025-44899CRITICALCVSS 9.8EG 9.82025-05-06
There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.
- CVE-2025-44900MEDIUMCVSS 6.5EG 6.52025-05-06
In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.
- CVE-2025-4498MEDIUMCVSS 5.3EG 5.32025-05-10
A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer ov…
- CVE-2025-4499MEDIUMCVSS 5.3EG 5.32025-05-10
A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].d…
- CVE-2025-4500MEDIUMCVSS 5.3EG 5.32025-05-10
A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of the component Edit Room. The manipulation of the argument roomnumber leads to st…
- CVE-2025-4501MEDIUMCVSS 5.3EG 5.32025-05-10
A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. The manipulation leads to stack-based buffer overflow. Local a…
- CVE-2025-45375MEDIUMCVSS 4.4EG 4.42025-10-07
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7…
- CVE-2025-45427CRITICALCVSS 9.8EG 9.82025-04-23
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
- CVE-2025-45428CRITICALCVSS 9.8EG 9.82025-04-23
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
- CVE-2025-45429CRITICALCVSS 9.8EG 9.82025-04-23
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.
- CVE-2025-4544MEDIUMCVSS 6.6EG 6.62025-05-11
A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_ma…
- CVE-2025-45513CRITICALCVSS 9.8EG 9.82025-05-09
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
- CVE-2025-45514MEDIUMCVSS 6.5EG 6.52025-05-07
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.
- CVE-2025-45587HIGHCVSS 7.0EG 7.02025-09-12
A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-45787CRITICALCVSS 9.8EG 9.82025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.
- CVE-2025-45788CRITICALCVSS 9.8EG 9.82025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
- CVE-2025-45789CRITICALCVSS 9.8EG 9.82025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
- CVE-2025-45790CRITICALCVSS 9.8EG 9.82025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.
- CVE-2025-45797CRITICALCVSS 9.8EG 9.82025-05-08
TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.
- CVE-2025-45841CRITICALCVSS 9.8EG 9.82025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
- CVE-2025-45842HIGHCVSS 8.8EG 8.82025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
- CVE-2025-45843HIGHCVSS 8.8EG 8.82025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
- CVE-2025-45844HIGHCVSS 8.8EG 8.82025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.
- CVE-2025-45845HIGHCVSS 8.8EG 8.82025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.
- CVE-2025-45846HIGHCVSS 8.8EG 8.82025-05-08
ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.
- CVE-2025-45847MEDIUMCVSS 6.5EG 6.52025-05-08
ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.
- CVE-2025-45862MEDIUMCVSS 6.5EG 6.52025-05-20
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.
- CVE-2025-45867MEDIUMCVSS 5.4EG 6.52025-05-13
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
- CVE-2025-46397HIGHCVSS 7.8EG 7.82025-04-23
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
- CVE-2025-46398HIGHCVSS 5.5EG 7.12025-04-23
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
- CVE-2025-46405HIGHCVSS 7.5EG 7.52025-08-13
When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not …
- CVE-2025-46411HIGHCVSS 8.1EG 8.12025-08-25
A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can pr…
- CVE-2025-46836MEDIUMCVSS 6.6EG 6.62025-05-14
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package…
- CVE-2025-47120MEDIUMCVSS 5.5EG 5.52025-07-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must …
- CVE-2025-47347HIGHCVSS 7.8EG 7.82025-10-09
Memory corruption while processing control commands in the virtual memory management interface.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →