Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-121 (栈缓冲区溢出) — Vulnerability Class 2922

2922 vulnerabilities classified as CWE-121 (栈缓冲区溢出). AI Chinese analysis included.

CWE-121 represents a critical memory safety weakness where program data exceeds the allocated bounds of a stack-allocated buffer, corrupting adjacent memory structures. Attackers typically exploit this vulnerability by injecting malicious payloads that overwrite the function’s return address or saved frame pointer, thereby hijacking control flow to execute arbitrary code with the privileges of the compromised process. This exploitation is particularly dangerous because stack buffers are local variables, making the attack surface common in low-level languages like C and C++. Developers mitigate this risk by enforcing strict input validation, utilizing safe string handling functions that prevent unbounded writes, and adopting modern programming languages with automatic memory management. Additionally, implementing compiler-level protections such as stack canaries and Address Space Layout Randomization significantly raises the barrier for successful exploitation, ensuring system integrity remains intact against buffer overflow attempts.

MITRE CWE Description
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Common Consequences (3)
Availability Modify Memory, DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
Buffer overflows generally lead to crashes. Other attacks leading to lack of availability are possible, including putting the program into an infinite loop.
Integrity, Confidentiality, Availability, Access Control Modify Memory, Execute Unauthorized Code or Commands, Bypass Protection Mechanism
Buffer overflows often can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy.
Integrity, Confidentiality, Availability, Access Control, Other Modify Memory, Execute Unauthorized Code or Commands, Bypass Protection Mechanism, Other
When the consequence is arbitrary code execution, this can often be used to subvert any other security service.
Mitigations (5)
Operation, Build and Compilation Use automatic buffer overflow detection mechanisms that are offered by certain compilers or compiler extensions. Examples include: the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice, which provide various mechanisms including canary-based detection and range/index checking. D3-SFCV (Stack Frame Canary Validation) from D3FEND [REF-1334] discusses…
Effectiveness: Defense in Depth
Architecture and Design Use an abstraction library to abstract away risky APIs. Not a complete solution.
Implementation Implement and perform bounds checking on input.
Implementation Do not use dangerous functions such as gets. Use safer, equivalent functions which check for boundary errors.
Operation, Build and Compilation Run or compile the software using features or extensions that randomly arrange the positions of a program's executable and libraries in memory. Because this makes the addresses unpredictable, it can prevent an attacker from reliably jumping to exploitable code. Examples include Address Space Layout Randomization (ASLR) [REF-58] [REF-60] and Position-Independent Executables (PIE) [REF-64]. Imported…
Effectiveness: Defense in Depth
Examples (2)
While buffer overflow examples can be rather complex, it is possible to have very simple, yet still exploitable, stack-based buffer overflows:
#define BUFSIZE 256 int main(int argc, char **argv) { char buf[BUFSIZE]; strcpy(buf, argv[1]); }
Bad · C
This example takes an IP address from a user, verifies that it is well formed and then looks up the hostname and copies it into a buffer.
void host_lookup(char *user_supplied_addr){ struct hostent *hp; in_addr_t *addr; char hostname[64]; in_addr_t inet_addr(const char *cp); /*routine that ensures user_supplied_addr is in the right format for conversion */ validate_addr_form(user_supplied_addr); addr = inet_addr(user_supplied_addr); hp = gethostbyaddr( addr, sizeof(struct in_addr), AF_INET); strcpy(hostname, hp->h_name); }
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-57166 PJSIP: Pre-authentication overflow in the telnet CLI error — pjproject 6.3 Medium 2026-09-04
CVE-2026-57165 PJSIP: Pre-authentication overflow in the telnet CLI history — pjproject 6.3 Medium 2026-09-04
CVE-2026-57163 PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend — pjproject 8.8 High 2026-09-04
CVE-2026-57162 PJSIP: Stack overflow parsing SDP a=crypto attributes — pjproject 8.8 High 2026-09-04
CVE-2026-57161 PJSIP: Stack overflow handling Service-Route headers in a registration response — pjproject 8.8 High 2026-09-04
CVE-2026-17259 IBM i is Affected By Multiple Vulnerabilities in Debug Server — i 4.3 Medium 2026-09-04
CVE-2026-17270 IBM i is Affected By Multiple Vulnerabilities in Debug Server — i 4.3 Medium 2026-09-04
CVE-2026-85509 FreeIPMI 1.6.19前 _read_fru_data 栈溢出 — FreeIPMI 9.8 Critical 2026-09-04
CVE-2026-85508 FreeIPMI 1.6.19 前 ipmi-oem-dell 栈溢出 — FreeIPMI 9.8 Critical 2026-09-04
CVE-2026-85507 FreeIPMI 1.6.19 栈缓冲区溢出 — FreeIPMI 9.8 Critical 2026-09-04
CVE-2026-85506 FreeIPMI 1.6.19 前 ipmi-oem 缓冲区溢出漏洞 — FreeIPMI 9.8 Critical 2026-09-04
CVE-2026-85504 FreeIPMI 1.6.19 前栈缓冲区溢出 — FreeIPMI 9.8 Critical 2026-09-04
CVE-2026-18167 Stack-based buffer overflow in TP-Link Archer AX55 v4 — Archer AX55 v4 7.7 High 2026-09-03
CVE-2026-73600 Dell PowerProtect DM 20.2.0 文件恢复代理栈溢出 — PowerProtect Data Manager 7.8 High 2026-09-03
CVE-2023-20577 AMD EPYC 安全漏洞 — 2nd Gen AMD EPYC™ Processors 7.4 High 2026-09-02
CVE-2026-84351 Chrome 152.0.7977.75 GPU缓冲区溢出漏洞 — Chrome - - 2026-09-01
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack — EtherNet/IP Adapter DLL Kit (EIPA) 9.8 Critical 2026-09-01
CVE-2026-12661 FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability — FactoryTalk® Historian Machine Edition 4.8 Medium 2026-09-01
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow — NR1800X 9.9 Critical 2026-08-31
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow — DIR-825M 9.9 Critical 2026-08-30
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow — DIR-825M 9.9 Critical 2026-08-30
CVE-2026-82478 NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow — Trick 7.3 High 2026-08-30
CVE-2026-75118 http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow — TL-MR100 v3.20 8.7 High 2026-08-28
CVE-2026-81533 MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values — BI Connector ODBC Driver 7.1 High 2026-08-28
CVE-2026-81532 BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption — BI Connector ODBC Driver 8.8 High 2026-08-28
CVE-2026-77218 PLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Credential Handlers — PLANET GS-4210-16P2S V3 4.9 Medium 2026-08-28
CVE-2026-77217 PLANET GS-4210-16P2S V3 Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi RADIUS Handlers — PLANET GS-4210-16P2S V3 4.9 Medium 2026-08-28
CVE-2026-75126 PLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Standard Handlers — PLANET GS-4210-16P2S V3 4.9 Medium 2026-08-28
CVE-2026-13086 Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint — Fireware OS 9.3 Critical 2026-08-27
CVE-2026-78010 Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service — Fireware OS 8.7 High 2026-08-27

Vulnerabilities classified as CWE-121 (栈缓冲区溢出) represent 2922 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.