← Back
CWE-121

3,522 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

JSON object

Loading...

CVEs (3,522)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GstreamerGstreamer Project
3Debian Linux
GstreamerGstreamer
Jun 17, 2026
May 22, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with...Show more
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of H265 slice headers. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26596.Show less
1Meddream
1Pacs Server
Jun 17, 2026
May 22, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Ser...Show more
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DICOM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-25853.Show less
1Meddream
1Pacs Server
Jun 17, 2026
May 22, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Ser...Show more
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DICOM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-25825.Show less
1Meddream
1Pacs Server
Jun 17, 2026
May 22, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Ser...Show more
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DICOM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-25826.Show less
1Meddream
1Pacs Server
Jun 17, 2026
May 22, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Ser...Show more
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DICOM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-25827.Show less
-
-
Jun 17, 2026
May 21, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerability to gain code execution on the device.
1Jqlang
1Jq
Jun 17, 2026
May 21, 2025
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, li...Show more
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions are available.Show less
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.
1Planet
1Wgs 804hpt Firmware
Jun 17, 2026
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.