CWE-121
Stack-based Buffer Overflow
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 50 of 92- CVE-2025-7019Medium· 5.58 h ago
Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast
- CVE-2025-52292High· 7.5EPSS 0%14 h ago
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-20352High· 7.7KEVEPSS 3%14 h ago
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
- CVE-2025-0282Critical· 9.0KEVEXPLOITEPSS 94%14 h ago
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
- CVE-2022-20701Critical· 10.0KEVEPSS 6%14 h ago
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
- CVE-2025-22457Critical· 9.0KEVEXPLOITEPSS 59%14 h ago
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
- CVE-2025-42599Critical· 9.8KEVEPSS 8%14 h ago
Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
- CVE-2025-53521Critical· 9.8KEVEPSS 9%14 h ago
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
- CVE-2022-20708Critical· 10.0KEVEPSS 9%14 h ago
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
- CVE-2022-20700Critical· 10.0KEVEPSS 29%14 h ago
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
- CVE-2020-5735High· 8.8KEVEXPLOITEPSS 50%14 h ago
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
- CVE-2021-20038Critical· 9.8KEVEPSS 94%14 h ago
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
- CVE-2025-62858Medium· 6.5EPSS 0%15 h ago
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have a
- CVE-2026-47959High· 7.8EPSS 0%16 h ago
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires
- CVE-2026-26239High· 8.1EPSS 0%18 h ago
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in
- CVE-2026-26240Critical· 9.1EPSS 0%18 h ago
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File
- CVE-2026-26241Critical· 9.1EPSS 0%18 h ago
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File
- CVE-2026-45648High· 8.8EPSS 0%1 d ago
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- CVE-2026-44815Critical· 9.8EPSS 0%1 d ago
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-0413—EPSS 0%1 d ago
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
- CVE-2026-49759—EPSS 0%2 d ago
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/comm
- CVE-2026-49760—EPSS 0%2 d ago
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term.
- CVE-2026-44634—EPSS 0%2 d ago
SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a stack overflow vulnerability in the dongl ba
- CVE-2026-36798Medium· 6.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSetDebugCfgr function via the enable, level, and module parameters. These vulnerabilities allow attackers to cause a Denial
- CVE-2026-36783High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the domain parameter of the fromNetToolGet function. This vulnerability allows attackers to cause a Denial of Service (
- CVE-2025-66280—EPSS 0%2 d ago
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of t
- CVE-2026-9669—EPSS 0%2 d ago
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal st
- CVE-2026-5713—EPSS 0%2 d ago
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that proces
- CVE-2026-36792High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formWifiRadioSet function. This vulnerability allows attackers to cause a Denial of Servi
- CVE-2026-36784High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the ip parameter of the fromNetToolGet function. This vulnerability allows attackers to cause a Denial of Service (DoS)
- CVE-2026-36779High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack overflows in the fromVirtualSer function via the puVar2, puVar1, __s2, __s1_00, and puVar3 parameters. These vulnerabilities
- CVE-2026-36794High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the R7WebsSecurityHandler function via the username and password parameters. These vulnerabilities allow attack
- CVE-2026-36793High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the formwrlSSIDset function via the mit_ssid and mis_ssid_index parameters. These vulnerabilities allow attacke
- CVE-2026-36791High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to contain a stack overflow in the save_list_data parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft
- CVE-2026-36778Medium· 4.9EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of
- CVE-2026-36777Medium· 6.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the param_1 parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS
- CVE-2026-36773Medium· 6.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability allows attackers to cause a Denial of Service (DoS)
- CVE-2026-36772Medium· 6.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service
- CVE-2026-36813High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (Do
- CVE-2026-36806High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (D
- CVE-2026-36805High· 7.5EPSS 0%2 d ago
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer overflows in the Saveqqlist function via the qqStr and markStr parameters. These vulnerabilities allow attackers to cause a Denial of Service (
- CVE-2026-34702High· 7.8EPSS 0%2 d ago
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera
- CVE-2026-34697High· 7.8EPSS 0%2 d ago
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera
- CVE-2026-34695High· 7.8EPSS 0%2 d ago
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera
- CVE-2026-34708High· 7.8EPSS 0%2 d ago
InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t
- CVE-2026-36822High· 7.5EPSS 0%3 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craf
- CVE-2026-36821High· 7.5EPSS 0%3 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS
- CVE-2026-36820High· 7.5EPSS 0%3 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Ser
- CVE-2026-36819High· 7.5EPSS 0%3 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a
- CVE-2026-36823High· 7.5EPSS 0%3 d ago
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS)
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.