CWE-121
CVEs classified under CWE-121, newest first.
345 CVEsRSS
CVE-2026-69722High· 8.8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69714High· 8.0Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-69689High· 8.0Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVE-2026-69686High· 8.8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69620High· 8.1Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69614High· 8.8Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-69510High· 8.1Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69508High· 7.8Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-69503High· 8.0Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.
CVE-2026-69467High· 7.8Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-69461High· 8.8Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
CVE-2026-69412High· 8.0Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
CVE-2026-69391High· 7.8Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69301High· 8.0Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVE-2026-69290High· 7.8Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2026-69277High· 7.8Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
CVE-2026-68878High· 8.0Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
CVE-2026-68838High· 8.0Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CVE-2026-68834High· 8.0Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CVE-2026-67379High· 8.5Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-62706High· 8.8Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-77101High· 7.5CommServe contained a stack-based buffer overflow issue affecting service availability
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-86514Medium· 6.3PoCA weakness has been identified in vgmstream up to r2117
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be ca…
CVE-2026-86509Critical· 9.6PoCA flaw has been found in D-Link DIR-895L A1_102b07
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be don…
CVE-2026-86318Medium· 5.3PoCA flaw has been found in java-json-tools json-patch up to 1.13
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…
CVE-2026-86296Critical· 10.0PoCA vulnerability was determined in D-Link DIR-822A A_101
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…
CVE-2026-81738Low· 2.3OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
CVE-2026-20509Medium· 6.7In Power HAL, there is a possible out of bounds write due to a missing bounds check
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for expl…
CVE-2026-86140High· 8.0In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVE-2026-85507Critical· 9.8ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).