VulnSea

CWE-121

CVEs classified under CWE-121, newest first.

345 CVEsRSS

CVE-2026-90558Critical· 9.8
2w ago

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or…

▾ Midnightirontec · sngrepEPSS 0.88%via NVD
CVE-2026-86093High· 7.5
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

▾ Twilightibm · db2EPSS 0.45%via NVD
CVE-2026-88268Medium· 6.5
2w ago

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

▾ SunlitGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.41%via NVD
CVE-2026-88047High· 7.8
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-88283Medium· 4.9
2w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via NVD
CVE-2026-15419High· 7.0
2w ago

CP210x Driver Memory Corruption results in Arbitrary Code Execution

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

▾ TwilightSilicon Labs · silabser.sys driverEPSS 0.17%via CVEORG
CVE-2026-82079High· 7.0
2w ago

Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted netw…

▾ TwilightNintendo · Nintendo SwitchEPSS 0.25%via CVEORG
CVE-2026-88281Medium· 4.9
2w ago

GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88280Medium· 4.9
2w ago

GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88279Medium· 4.9
2w ago

GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-42805High· 8.4
2w ago

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c)

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events a…

▾ TwilightBosch Sensortec · BHI385 SensorAPI (C Library)EPSS 0.19%via NVD
CVE-2026-42804High· 7.6
2w ago

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem …

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem …

▾ TwilightBosch Sensortec · BHI360_SensorAPI (C-Library)EPSS 0.25%via NVD
CVE-2026-88284Medium· 4.9
2w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211 -EPSS 0.44%via NVD
CVE-2026-88289High· 7.5
2w ago

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash t…

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash t…

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.57%via NVD
CVE-2026-88287High· 7.5
2w ago

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.55%via NVD
CVE-2026-21093Medium· 6.7
2w ago

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-85384High· 8.5
2w ago

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local n…

▾ TwilightTP-Link Systems Inc. · RE210 AC750EPSS 0.32%via NVD
CVE-2026-9216Low· 3.5
2w ago

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality o…

▾ Sunlitnetgear · rax30_firmwareEPSS 0.36%via NVD
CVE-2026-83990High· 7.8
2w ago

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.33%via NVD
CVE-2026-81953High· 7.8
2w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · 365_appsEPSS 0.47%via NVD
CVE-2026-81396High· 7.8
2w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · 365_appsEPSS 0.47%via NVD
CVE-2026-81388High· 7.8
2w ago

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · 365_appsEPSS 0.47%via NVD
CVE-2026-78504High· 8.8
2w ago

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78439High· 8.8
2w ago

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Office 365 for MacEPSS 0.84%via NVD
CVE-2026-73006High· 8.8
2w ago

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-72982Critical· 9.8
2w ago

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-71337High· 7.8
2w ago

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_21h2EPSS 0.33%via NVD
CVE-2026-69910Critical· 9.8
2w ago

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-69762High· 8.0
2w ago

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.77%via NVD
CVE-2026-69759High· 8.8
2w ago

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CWE-121 vulnerabilities (CVEs) — page 3 · VulnSea