CWE-121
3,519 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CVEs (3,519)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web administration interface HNAP service. |
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (...Show more |
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based...Show more |
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's lengt...Show more |
1We Con 1Levi Studio Hmi Editor May 13, 2026 Oct 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Stack-based Buffer Overflow issue was discovered in WECON LEVI Studio HMI Editor v1.8.1 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified in which the application does not verify stri...Show more |
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute...Show more |
1Ge 1Intelligent Platforms Proficy Hmi/scada Cimplicity May 13, 2026 Oct 5, 2017 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrit...Show more |
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of...Show more |
1Spidercontrol 1Scada Microbrowser May 13, 2026 Aug 25, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow. |
A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35,...Show more |
1Nxp 27I.mx 50 Firmware I.mx 53 FirmwareI.mx 6dual Firmware+24 moreMay 13, 2026 Aug 7, 2017 N/A· v4 6.3 MEDIUM· v3 4.4 MEDIUM· v2 A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vyb...Show more |
1Schneider Electric 1Wonderware Archestra Logger May 13, 2026 Jul 7, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow...Show more |
1Digital Canal Structural 1Wind Analysis May 13, 2026 Jun 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-...Show more |
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affec...Show more |
1Vipa Controls 1Winplc7 Firmware May 13, 2026 May 19, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability has been identified, where an attacker with a specially crafted packet could overfl...Show more |
A Stack-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow, which could result in denial of service when a malicious project...Show more |
1Fatek 4Ethernet Module Configuration Tool Cbe Firmware Ethernet Module Configuration Tool Cbeh FirmwareEthernet Module Configuration Tool Cm25e Firmware+1 moreMay 13, 2026 Mar 16, 2017 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 B...Show more |
1Rockwellautomation 2Micrologix 1100 Firmware Micrologix 1400 FirmwareJun 3, 2026 Oct 28, 2015 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors. |
1Schneider Electric 4Somachine SomoveSomove Lite+1 moreMay 6, 2026 Feb 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Libra...Show more |
1Schneider Electric 1Wonderware Intouch Access Anywhere Server May 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist. |