CWE-121
3,519 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CVEs (3,519)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and con...Show more |
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulner...Show more |
2Ami Intel3Aptio V Nuc M15 Laptop Kit Lapbc510 FirmwareNuc M15 Laptop Kit Lapbc710 FirmwareJun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolate...Show more |
2Ami Intel3Aptio V Nuc M15 Laptop Kit Lapbc510 FirmwareNuc M15 Laptop Kit Lapbc710 FirmwareJun 17, 2026 Sep 20, 2022 N/A· v4 8.2 HIGH· v3 N/A· v2 A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any...Show more |
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parse...Show more |
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverf...Show more |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to cra...Show more |
1Ezviz 5Cs C3w A0 3h4wfrl Firmware Cs C6n A0 1c2wfr FirmwareCs C6n B0 1g2wf Firmware+2 moreJun 17, 2026 Sep 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to ex...Show more |
1Dell 25Chengming 3900 Firmware Inspiron 14 Plus 7420 FirmwareInspiron 16 Plus 7620 Firmware+22 moreJun 17, 2026 Sep 12, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary co...Show more |
1Dell 399Alienware M15 R6 Firmware Chengming 3980 FirmwareChengming 3988 Firmware+396 moreJun 17, 2026 Sep 6, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution...Show more |
1Eset 2Endpoint Encryption Full Disk EncryptionJun 17, 2026 Sep 6, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD. |
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service. |
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. |
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file. |
1Fujielectric 1Alpha7 Pc Loader Firmware Jun 17, 2026 Aug 31, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted project file, which may allow an attacker to execute arbitrary code. |
CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition. |