Threats Tagged 'cwe-121'
View all threats tagged with 'cwe-121'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-121'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-67866: n/aCVE-2026-67866 0 A buffer overflow vulnerability exists in Systerel S2OPC version 1.7.3. This flaw allows a remote attacker to cause a denial of service by exploiting the client wrapper functions DeleteMonitoredItems path, specifically via LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems. Join the discussion | GCVE Database | 08/05/2026, 00:00:00 UTC Added: 08/06/2026, 18:16:34 UTC |
CVE-2026-18909: CWE-121 Stack-based buffer overflow in ELAN Microelectronics Corp. ELAN Smart-PadCVE-2026-18909 0 A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3. Join the discussion | CVE Database V5 | 08/06/2026, 03:46:00 UTC Added: 08/06/2026, 04:26:48 UTC |
CVE-2026-71267: CWE-121 in rxi microtarCVE-2026-71267 0 microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow. Join the discussion | CVE Database V5 | 08/05/2026, 12:26:14 UTC Added: 08/05/2026, 13:13:08 UTC |
CVE-2026-71266: CWE-121 in syoyo tinyobjloader-cCVE-2026-71266 0 tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer `linebuf` via memcpy(linebuf, p, p_len), guarded only by `assert(p_len < 4095)`. Because assert() compiles to a no-op under -DNDEBUG (standard for release builds), a crafted .mtl file containing a line (e.g. a "newmtl" material name) longer than 4096 bytes overflows linebuf into the adjacent stack variable namebuf and beyond, corrupting the stack of any application that loads attacker-supplied 3D model/material files. The identical vulnerable pattern is duplicated in a second function in the same file. Join the discussion | CVE Database V5 | 08/05/2026, 12:26:14 UTC Added: 08/05/2026, 13:13:08 UTC |
CVE-2026-61486: CWE-121 Stack-based Buffer Overflow in Apache Software Foundation Apache LucyCVE-2026-61486 0 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Join the discussion | CVE Database V5 | 08/05/2026, 06:44:11 UTC Added: 08/05/2026, 07:27:05 UTC |
CVE-2026-49435: CWE-121 Stack-based Buffer Overflow in Keysight HawkeyeCVE-2026-49435 0 Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges. Join the discussion | CVE Database V5 | 08/04/2026, 18:52:30 UTC Added: 08/04/2026, 19:05:20 UTC |
CVE-2026-25289: CWE-121 Stack-based Buffer Overflow in Qualcomm, Inc. SnapdragonCVE-2026-25289 0 Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. Join the discussion | CVE Database V5 | 08/04/2026, 15:07:23 UTC Added: 08/04/2026, 15:42:05 UTC |
CVE-2026-10710: CWE-121 Stack-based Buffer Overflow in Autodesk FBX SDKCVE-2026-10710 0 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 08/04/2026, 12:59:51 UTC Added: 08/04/2026, 13:42:26 UTC |
CVE-2026-10709: CWE-121 Stack-based Buffer Overflow in Autodesk FBX SDKCVE-2026-10709 0 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 08/04/2026, 12:59:07 UTC Added: 08/04/2026, 13:42:26 UTC |
CVE-2026-10535: CWE-121 Stack-based Buffer Overflow in IBM Db2CVE-2026-10535 0 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. Join the discussion | CVE Database V5 | 07/30/2026, 16:55:57 UTC Added: 07/30/2026, 17:23:15 UTC |
Showing 1 to 10 of 55 results