CVE-2025-7704Medium· 5.4▾ SunlitSupermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-1761High· 8.6A flaw was found in libsoup
CVE-2026-24882High· 8.4In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
CVE-2026-24881High· 8.1In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling
CVE-2026-0719High· 8.6A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication
CVE-2025-11918High· 7.3Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability
CVE-2025-66635High· 7.2Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config