CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,576 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 52 of 72
- CVE-2025-5849HIGHCVSS 8.8EG 8.82025-06-08
A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation …
- CVE-2025-5853HIGHCVSS 8.8EG 8.82025-06-09
A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg. The manipulation of the argument remoteIp leads to stack-ba…
- CVE-2025-5855CRITICALCVSS 9.8EG 9.82025-06-09
A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer…
- CVE-2025-5863CRITICALCVSS 9.8EG 9.82025-06-09
A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer…
- CVE-2025-58775HIGHCVSS 7.8EG 7.82025-10-02
KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
- CVE-2025-58776HIGHCVSS 7.8EG 7.82025-10-02
KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
- CVE-2025-5912HIGHCVSS 8.8EG 8.82025-06-10
A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The …
- CVE-2025-59149MEDIUMCVSS 6.2EG 6.22025-10-01
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can …
- CVE-2025-59251HIGHCVSS 7.6EG 7.62025-09-24
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-5934HIGHCVSS 8.8EG 8.82025-06-10
A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. The manipulation leads to stack-based buffer overflow. It is possible to launch the attac…
- CVE-2025-59362HIGHCVSS 4.0EG 8.22025-09-26
Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
- CVE-2025-59365MEDIUMCVSS 6.9EG 6.92025-11-25
A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the …
- CVE-2025-59383CRITICALCVSS 9.1EG 9.12026-03-20
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following vers…
- CVE-2025-59612MEDIUMCVSS 6.7EG 6.72026-06-01
Memory corruption in windows drivers while sending incorrect trusted application request
- CVE-2025-59613MEDIUMCVSS 6.7EG 6.72026-06-01
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
- CVE-2025-5969HIGHCVSS 8.8EG 8.82025-06-10
A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /biurl_grou of the component HTTP POST Request Handler. The manipulation leads to…
- CVE-2025-5978HIGHCVSS 8.8EG 8.82025-06-10
A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It …
- CVE-2025-59798MEDIUMCVSS 4.3EG 4.32025-09-22
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
- CVE-2025-59799MEDIUMCVSS 4.3EG 4.32025-09-22
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.
- CVE-2025-59801MEDIUMCVSS 4.3EG 4.32025-09-22
In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.
- CVE-2025-60331HIGHCVSS 7.5EG 7.52025-10-22
D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60333HIGHCVSS 7.5EG 7.52025-10-22
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60334HIGHCVSS 7.5EG 7.52025-10-22
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60341HIGHCVSS 7.5EG 7.52025-10-22
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60342HIGHCVSS 7.5EG 7.52025-10-22
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60474HIGHCVSS 7.5EG 7.52026-06-24
A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- CVE-2025-60547HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.
- CVE-2025-60549HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.
- CVE-2025-60550HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.
- CVE-2025-60551HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.
- CVE-2025-60552HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.
- CVE-2025-60555HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.
- CVE-2025-60556HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.
- CVE-2025-60557HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.
- CVE-2025-60558HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.
- CVE-2025-60559HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.
- CVE-2025-60561HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.
- CVE-2025-60562HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.
- CVE-2025-60563HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.
- CVE-2025-60564HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.
- CVE-2025-60565HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.
- CVE-2025-60566HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.
- CVE-2025-60568HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.
- CVE-2025-60569HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.
- CVE-2025-60570HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.
- CVE-2025-60571HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.
- CVE-2025-60572HIGHCVSS 7.5EG 7.52025-10-24
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.
- CVE-2025-60660HIGHCVSS 7.5EG 7.52025-10-02
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.
- CVE-2025-60661MEDIUMCVSS 5.3EG 5.32025-10-02
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.
- CVE-2025-60662HIGHCVSS 7.5EG 7.52025-10-02
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →