← Back
CWE-121

3,519 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

JSON object

Loading...

CVEs (3,519)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jun 10, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This iss...Show more
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 13, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of P...Show more
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.Show less
1Advantech
1Webaccess
Jun 17, 2026
May 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remo...Show more
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.Show less
1Abbs Software Audio Media Player Project
1Abbs Software Audio Media Player
Jun 17, 2026
Apr 29, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
1Aasync
1Aasync
Jun 17, 2026
Apr 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
1A Pdf
1Wav To Mp3
Jun 17, 2026
Apr 29, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
1Trianglemicroworks
1Dnp3 Source Code Library
Jun 17, 2026
Apr 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-b...Show more
Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability.Show less
1Trianglemicroworks
1Scada Data Gateway
Jun 17, 2026
Apr 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied da...Show more
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based buffer. Authentication is not required to exploit this vulnerability.Show less
1Eaton
1Hmisoft Vu3 Firmware
Jun 17, 2026
Apr 15, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the af...Show more
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the affected product.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges. This iss...Show more
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges. This issue affects Palo Alto Networks PAN-OS 8.1 versions before 8.1.13; 9.0 versions before 9.0.7. This issue does not affect PAN-OS 7.1.Show less
1Amcrest
181080 Lite 8ch Firmware
Amdv10814 H5 FirmwareIp2m 841 V3 Firmware+15 more
Jun 17, 2026
Apr 8, 2020
N/A· v4
8.8 HIGH· v3
8.0 HIGH· v2
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
1Visam
2Vbase Editor
Vbase Web Remote
Jun 17, 2026
Apr 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of ar...Show more
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.Show less
4Canonical
DebianPhp+1 more
4Debian Linux
PhpTenable.sc+1 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memor...Show more
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.Show less
1Dell
3Idrac7 Firmware
Idrac8 FirmwareIdrac9 Firmware
Jun 17, 2026
Mar 31, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the...Show more
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.Show less
1Advantech
1Webaccess
Jun 17, 2026
Mar 27, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.
1Tp Link
1Ac1750 Firmware
Jun 17, 2026
Mar 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The s...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9660.Show less
1Moxa
2Eds 510e Firmware
Eds G516e Firmware
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.
1Moxa
55Pt 7528 12msc 12tx 4gsfp Hv Hv Firmware
Pt 7528 12msc 12tx 4gsfp Hv FirmwarePt 7528 12msc 12tx 4gsfp Wv Wv Firmware+52 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows remote attackers to cause a denial-of-service condition or execute arbi...Show more
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows remote attackers to cause a denial-of-service condition or execute arbitrary code.Show less
1Deltaww
1Cncsoft Screeneditor
Jun 17, 2026
Mar 18, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.
1Moxa
1Awk 3131a Firmware
Jun 17, 2026
Feb 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an er...Show more
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.Show less