VulnSea

CWE-121

CVEs classified under CWE-121, newest first.

345 CVEsRSS

CVE-2026-85506Critical· 9.8
3w ago

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

▾ MidnightFreeIPMI · FreeIPMIEPSS 0.40%via NVD
CVE-2026-57166Medium· 5.3⚖ disputed
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. Several co…

▾ Sunlitteluu · pjsipEPSS 0.53%via NVD
CVE-2026-57163Critical· 9.1
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (t…

▾ Midnightteluu · pjsipEPSS 0.40%via NVD
CVE-2026-57162Critical· 9.1
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_enc…

▾ Midnightteluu · pjsipEPSS 0.64%via NVD
CVE-2026-57161High· 8.2
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when processing Service-Route headers in a registration response (update_service_route() in p…

▾ Twilightteluu · pjsipEPSS 0.46%via NVD
CVE-2026-85509Critical· 9.8
3w ago

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

▾ MidnightEPSS 0.40%via NVD
CVE-2026-85508Critical· 9.8
3w ago

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

▾ MidnightEPSS 0.40%via NVD
CVE-2026-85504Critical· 9.8
3w ago

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

▾ MidnightEPSS 0.40%via NVD
CVE-2026-57165Medium· 5.3⚖ disputed
3w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_u…

▾ Sunlitteluu · pjsipEPSS 0.45%via NVD
CVE-2026-17270Medium· 4.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.

▾ Sunlitibm · iEPSS 0.21%via NVD
CVE-2026-17259Medium· 4.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

▾ Sunlitibm · iEPSS 0.36%via NVD
CVE-2026-18167None
3w ago

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-78012Critical· 9.8
3w ago

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-82478High· 7.3
4w ago

A vulnerability was determined in NASA Trick 19.6.0

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socke…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-81533High· 7.1
1mo ago

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where th…

▾ Twilightmongodb · bi_connector_odbc_driverEPSS 0.37%via NVD
CVE-2026-81532High· 8.8
1mo ago

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is no…

▾ Twilightmongodb · bi_connector_odbc_driverEPSS 0.49%via NVD
CVE-2026-77218Medium· 4.9
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buff…

▾ SunlitEPSS 0.57%via NVD
CVE-2026-77217Medium· 4.9
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radK…

▾ SunlitEPSS 0.60%via NVD
CVE-2026-75126Medium· 4.9
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack …

▾ SunlitEPSS 0.60%via NVD
CVE-2026-19318None
1mo ago

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ SunlitEPSS 0.47%via NVD
CVE-2026-13086None
1mo ago

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-75421Medium· 4.0
1mo ago

aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

▾ SunlitEPSS 0.16%via NVD
CVE-2026-76071Critical· 9.8PoC
1mo ago

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod…

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod…

▾ AbyssalEPSS 1.4%via NVD
CVE-2026-76070Critical· 9.8PoC
1mo ago

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login hand…

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login hand…

▾ AbyssalEPSS 1.3%via NVD
CVE-2025-36939Medium· 5.7
1mo ago

Multiple vulnerabilities exist in OpenThread's handling of MLE packets

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion fa…

▾ Sunlitgoogle · nest_wifi_router_firmwareEPSS 0.21%via NVD
CVE-2026-68516Medium· 6.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-75368High· 7.5
1mo ago

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-77946Critical· 10.0
1mo ago

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulatio…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

▾ Midnightlibevent · libeventEPSS 0.45%via NVD
CVE-2026-16945High· 7.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.

▾ TwilightEPSS 0.17%via NVD
CWE-121 vulnerabilities (CVEs) — page 5 · VulnSea