VulnSea

CWE-121

CVEs classified under CWE-121, newest first.

287 CVEsRSS

CVE-2026-90680Critical· 9.9
1w ago

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/…

MidnightD-Link · DIR-823GEPSS 0.51%via NVD
CVE-2026-90688Medium· 6.5PoC
1w ago

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overf…

TwilightTenda · W20EEPSS 0.40%via NVD
CVE-2023-46273High· 8.8
1w ago

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Twilightextremenetworks · IQ EngineEPSS 0.31%via NVD
CVE-2026-90693Critical· 9.9PoC
1w ago

A flaw has been found in D-Link DIR-878 120B05

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…

AbyssalD-Link · DIR-878EPSS 0.47%via NVD
CVE-2026-90692Critical· 9.9
1w ago

A vulnerability was detected in D-Link DIR-878 120B05

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer ov…

MidnightD-Link · DIR-878EPSS 0.47%via NVD
CVE-2026-90689High· 8.8
1w ago

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. Th…

TwilightTenda · W20EEPSS 0.60%via NVD
CVE-2026-82785Medium· 4.3
1w ago

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.30%via NVD
CVE-2026-54559Medium· 6.9
1w ago

PocketSphinx is a small speech recognizer

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loader…

Sunlitcmusphinx · pocketsphinxEPSS 0.32%via NVD
CVE-2026-90779High· 7.5
1w ago

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …

TwilightRed Hat · sippEPSS 0.56%via NVD
CVE-2026-90558Critical· 9.8
1w ago

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or…

Midnightirontec · sngrepEPSS 0.51%via NVD
CVE-2026-86093High· 7.5
1w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

Twilightibm · db2EPSS 0.48%via NVD
CVE-2026-88268Medium· 6.5
1w ago

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

SunlitGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.24%via NVD
CVE-2026-88047High· 7.8
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.11%via NVD
CVE-2026-88283Medium· 4.9
1w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.25%via NVD
CVE-2026-15419High· 7.0
1w ago

CP210x Driver Memory Corruption results in Arbitrary Code Execution

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

TwilightSilicon Labs · silabser.sys driverEPSS 0.17%via CVEORG
CVE-2026-82079High· 7.0
1w ago

Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted netw…

TwilightNintendo · Nintendo SwitchEPSS 0.16%via CVEORG
CVE-2026-88281Medium· 4.9
1w ago

GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.25%via CVEORG
CVE-2026-88280Medium· 4.9
1w ago

GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.25%via CVEORG
CVE-2026-88279Medium· 4.9
1w ago

GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.25%via CVEORG
CVE-2026-42805High· 8.4
1w ago

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c)

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events a…

TwilightBosch Sensortec · BHI385 SensorAPI (C Library)EPSS 0.14%via NVD
CVE-2026-42804High· 7.6
1w ago

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem …

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem …

TwilightBosch Sensortec · BHI360_SensorAPI (C-Library)EPSS 0.25%via NVD
CVE-2026-88284Medium· 4.9
1w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211 -EPSS 0.25%via NVD
CVE-2026-88289High· 7.5
1w ago

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash t…

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash t…

TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.33%via NVD
CVE-2026-88287High· 7.5
1w ago

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.31%via NVD
CVE-2026-21093Medium· 6.7
1w ago

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-85384High· 8.5
1w ago

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local n…

TwilightTP-Link Systems Inc. · RE210 AC750EPSS 0.21%via NVD
CVE-2026-9216Low· 3.5
1w ago

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality o…

Sunlitnetgear · rax30_firmwareEPSS 0.23%via NVD
CVE-2026-83990High· 7.8
1w ago

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_11_23h2EPSS 0.28%via NVD
CVE-2026-81953High· 7.8
1w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Twilightmicrosoft · 365_appsEPSS 0.43%via NVD
CVE-2026-81396High· 7.8
1w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Twilightmicrosoft · 365_appsEPSS 0.42%via NVD
CWE-121 vulnerabilities (CVEs) — page 2 · VulnSea