CWE-121: Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
3,026 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-22457 — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
- CVE-2025-53521 — BigIP APM Vulnerability
- CVE-2025-32756 — A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
- CVE-2025-42599 — Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp
- CVE-2025-22467 — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to
- CVE-2025-34127 — Achat v0.150 SEH Buffer Overflow via UDP
- CVE-2025-34107 — WinaXe 7.7 FTP Client Remote Buffer Overflow
- CVE-2026-2329 — Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
- CVE-2025-20352 — A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
- CVE-2021-27137 — An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling function
- CVE-2026-0826 — Poly Voice – Possible Remote Control of Certain Poly Devices
- CVE-2025-5623 — D-Link DIR-816 qosClassifier stack-based overflow
- CVE-2025-5630 — D-Link DIR-816 form2lansetup.cgi stack-based overflow
- CVE-2025-5624 — D-Link DIR-816 QoSPortSetup stack-based overflow
- CVE-2026-4567 — Tenda A15 UploadCfg stack-based overflow
- CVE-2026-4254 — Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow
- CVE-2026-4184 — D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow
- CVE-2026-4183 — D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow
- CVE-2026-4182 — D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow
- CVE-2026-4181 — D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow
Recently published
- CVE-2026-85384 — Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
- CVE-2026-9216 — Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
- CVE-2026-86514 — vgmstream txth-txtp txth.c sscanf stack-based overflow
- CVE-2026-86509 — D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow
- CVE-2026-86318 — java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-based overflow
- CVE-2026-86296 — D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow
- CVE-2026-81738 — OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write
- CVE-2026-20509 — In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
- CVE-2026-86140 — In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
- CVE-2026-57166 — PJSIP: Pre-authentication overflow in the telnet CLI error
- CVE-2026-57165 — PJSIP: Pre-authentication overflow in the telnet CLI history
- CVE-2026-57163 — PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
- CVE-2026-57162 — PJSIP: Stack overflow parsing SDP a=crypto attributes
- CVE-2026-57161 — PJSIP: Stack overflow handling Service-Route headers in a registration response
- CVE-2026-17259 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-17270 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-85509 — FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC retu
- CVE-2026-85508 — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-o
- CVE-2026-85507 — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ip
- CVE-2026-85506 — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipm