Vulnerabilities (CVE)

Filtered by CWE-121
Total 3793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-30649 1 Vivotek 2 Fd8136, Fd8136 Firmware 2026-07-22 N/A 7.3 HIGH
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component
CVE-2026-1871 1 Tp-link 2 Tapo C200, Tapo C200 Firmware 2026-07-22 N/A 6.5 MEDIUM
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.
CVE-2026-35083 1 Mbs-solutions 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more 2026-07-22 N/A 8.8 HIGH
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35716 1 Vivotek 2 Fd8136, Fd8136 Firmware 2026-07-22 N/A 6.3 MEDIUM
A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.
CVE-2026-50031 2026-07-22 N/A 7.5 HIGH
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
CVE-2026-49943 2026-07-22 N/A 6.3 MEDIUM
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-size stack array of 2048 + 1 pm_pos entries, while parse_path() expands AS_PATH segments from a received BGP UPDATE without enforcing a corresponding capacity limit. When RFC 8654 BGP Extended Messages are enabled and a BIRD filter evaluates an AS path mask expression such as "bgp_path ~ [= ... =]", an established BGP peer can send a long AS_PATH containing more than 2048 expanded ASNs. This causes parse_path()/as_path_match() to write beyond the fixed stack buffer, resulting in a crash of the daemon. NOTE: reportedly, the Supplier's position is that a fix is not being prioritized because all network operators should already be rejecting routes with unusually long attributes.
CVE-2026-35084 1 Mbs-solutions 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more 2026-07-22 N/A 8.8 HIGH
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
CVE-2026-35717 1 Vivotek 2 Fd8136, Fd8136 Firmware 2026-07-22 N/A 6.3 MEDIUM
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.
CVE-2026-35085 1 Mbs-solutions 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more 2026-07-22 N/A 8.8 HIGH
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVE-2026-10528 2026-07-22 1.7 LOW 3.3 LOW
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.
CVE-2025-59613 1 Qualcomm 88 Cologne, Cologne Firmware, Fastconnect 6700 and 85 more 2026-07-22 N/A 6.7 MEDIUM
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612 1 Qualcomm 62 Cologne, Cologne Firmware, Fastconnect 6700 and 59 more 2026-07-22 N/A 6.7 MEDIUM
Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2026-10293 2026-07-22 9.0 HIGH 8.8 HIGH
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2026-10292 2026-07-22 9.0 HIGH 8.8 HIGH
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
CVE-2026-24085 1 Qualcomm 546 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Apq8098 and 543 more 2026-07-22 N/A 7.2 HIGH
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2026-57091 1 Microsoft 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more 2026-07-22 N/A 7.8 HIGH
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50695 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-07-22 N/A 7.5 HIGH
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50400 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-07-22 N/A 7.8 HIGH
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50387 1 Microsoft 16 365 Copilot, Microsoft 365, Office 2021 and 13 more 2026-07-22 N/A 7.8 HIGH
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-50304 1 Microsoft 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more 2026-07-22 N/A 7.5 HIGH
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.