By weakness (CWE)

CWE-121: related vulnerabilities

CVEs classified under CWE-121. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

153 published vulnerabilities · page 1 of 2

  • CVE-2026-10062HIGH 8.8

    A stack-based buffer overflow vulnerability was discovered in the TRENDnet TEW-432BRP router (firmware version 3.10B20) affecting the route configuration function. An authenticated attacker can send specially crafted requests containing oversized IP, netmask, or gateway parameters to the /goform/formSetRoute endpoint, causing a buffer overflow that enables complete compromise of the device. The vulnerability requires valid login credentials but has been publicly disclosed. Critically, this device reached end-of-life in 2009—over 15 years ago—and the vendor has confirmed no patches or fixes will be developed.

  • CVE-2026-10063HIGH 8.8

    A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) that allows authenticated attackers to remotely crash the device or potentially execute arbitrary code. The flaw is in the WPS (Wi-Fi Protected Setup) configuration function and can be triggered by sending a specially crafted request with an oversized PIN parameter. Critically, this router model reached end-of-life in 2009—over 15 years ago—and TRENDnet has confirmed they will not be providing patches or fixes.

  • CVE-2026-10065HIGH 8.8

    Shibby Tomato 1.28 contains a stack-based buffer overflow vulnerability in the UPS data retrieval function of its web interface. An authenticated attacker can manipulate the Date parameter to overflow a buffer on the stack, potentially executing arbitrary code on the affected device. Since Shibby Tomato is no longer maintained and has been superseded by FreshTomato, this vulnerability affects legacy installations that have not migrated to the actively supported successor.

  • CVE-2026-10066HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Shibby Tomato firmware versions up to 1.28, specifically in the UPS Service component (tomatoups.cgi). An authenticated attacker with remote network access can trigger this flaw to potentially execute arbitrary code, compromise confidentiality and integrity, or cause denial of service. Notably, Shibby Tomato is no longer maintained; the project has been superseded by FreshTomato. Organizations still running unsupported Shibby Tomato instances face ongoing risk from this flaw without vendor patching.

  • CVE-2026-10067HIGH 8.8

    Shibby Tomato version 1.28 contains a stack-based buffer overflow vulnerability in the multimon.cgi component that allows authenticated attackers to execute arbitrary code remotely. The vulnerability exists in the sub_90F0 function and can be triggered through network requests without user interaction. Since Shibby Tomato is no longer maintained and has been superseded by FreshTomato, patches are not available from the original maintainers.

  • CVE-2026-10119HIGH 8.8

    A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP router (firmware version 3.10B20) in the MAC filter configuration function. An authenticated attacker can send a specially crafted request to overflow the stack via the filter_name parameter, potentially allowing code execution on the device. This affects only legacy hardware that has been end-of-life since 2009—the vendor has explicitly stated no patches will be released due to the product's age and lack of ongoing support.

  • CVE-2026-10120HIGH 8.8

    A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. An attacker with network access and valid credentials can send a specially crafted request to the firewall configuration function, causing a buffer overflow that crashes the device or potentially executes arbitrary code. The vendor has confirmed the product reached end-of-life in 2009 and will not issue patches. Public exploit code is available.

  • CVE-2026-10121HIGH 8.8

    A stack-based buffer overflow vulnerability has been discovered in the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. The flaw exists in the URL filter configuration function and can be triggered by sending a specially crafted request containing an oversized keyword list parameter. An attacker with network access and valid credentials can exploit this remotely to crash the device or potentially execute arbitrary code. TRENDnet has confirmed the product reached end-of-life in 2009 and will not be issuing patches.

  • CVE-2026-10122HIGH 8.8

    A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) within the protocol filter configuration function. An attacker with network access and valid login credentials can send a specially crafted request to overflow a buffer on the router's stack, potentially executing arbitrary code. TRENDnet has confirmed this product reached end-of-life 15 years ago and will not provide patches. While the exploit details are publicly available, this vulnerability poses limited enterprise risk due to the device's age and likely scarcity in production environments.

  • CVE-2026-10123HIGH 8.8

    A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) affecting the domain filtering function. An authenticated attacker can exploit this by manipulating domain filter parameters to overflow the stack, potentially gaining control of the device. Notably, this product reached end-of-life in 2009 and is no longer supported by the vendor, meaning no patches will be issued.

  • CVE-2026-10124HIGH 8.8

    A stack-based buffer overflow has been discovered in Shibby Tomato, a Linux router distribution, affecting versions up to 1.28. The vulnerability exists in the RIP (Routing Information Protocol) daemon's IPv4 handling function and allows authenticated attackers to overflow memory on the system stack, potentially leading to code execution. The flaw has been publicly disclosed, and exploit code is available. Critically, Shibby Tomato is no longer maintained by its original developers, having been superseded by FreshTomato. This means no security patches will be released for affected installations.

  • CVE-2026-10125HIGH 8.8

    A stack-based buffer overflow exists in Edimax BR-6478AC version 1.23 routers when processing PPPoE setup requests. An authenticated attacker can send a crafted request with an oversized username parameter to the formPPPoESetup endpoint, causing the router to crash or potentially execute arbitrary code. The vulnerability requires login credentials but poses significant risk since routers are often accessible from the internet and public exploit code is available.

  • CVE-2026-10158HIGH 8.8

    A stack-based buffer overflow has been discovered in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated attacker can send a specially crafted request to the port forwarding configuration interface, exploiting improper input validation on the server_name parameter. This can lead to remote code execution on the device. The vulnerability is particularly concerning because exploit code has already been released publicly. However, the affected product reached end-of-life in 2009 and the vendor has stated they cannot provide patches.

  • CVE-2026-10159HIGH 8.8

    A stack-based buffer overflow vulnerability has been discovered in the TRENDnet TEW-432BRP wireless router (version 3.10B20), specifically in the system log configuration function. An attacker with network access and valid credentials can send a specially crafted request to trigger a memory overflow, potentially executing arbitrary code on the device. The vendor has confirmed the product reached end-of-life in 2009 and will not be patching this issue.

  • CVE-2026-10160HIGH 8.8

    A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated attacker can exploit this flaw by manipulating the 'start_wizard' parameter sent to the router's web interface, potentially allowing remote code execution. The vendor has confirmed this product reached end-of-life in 2009 and will not issue patches.

  • CVE-2026-10161HIGH 8.8

    A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) in a network-accessible configuration function. An authenticated attacker can send a specially crafted request to the `/goform/formResetStatistic` endpoint with a malicious `status_statistic` parameter that overflows memory and corrupts the stack, potentially leading to code execution or denial of service. The device has been out of support since 2009, and the vendor has explicitly stated they cannot patch this issue.

  • CVE-2026-10162HIGH 8.8

    TRENDnet's TEW-432BRP wireless router (version 3.10B20) contains a stack-based buffer overflow vulnerability in its password-setting function. An authenticated attacker can send specially crafted input to the formSetPassword endpoint to overflow memory and potentially execute code on the device. The device has been end-of-life since 2009, and the vendor explicitly will not release patches. While the attack requires login credentials, the high CVSS score reflects the severity of potential compromise.

  • CVE-2026-10165HIGH 8.8

    Edimax BR-6478AC wireless routers running firmware version 1.23 contain a critical flaw in their network configuration interface. An authenticated attacker can send a specially crafted network request to overflow the device's memory, potentially gaining complete control over the router. The vulnerability requires an existing user account but no additional interaction from administrators, making it a practical concern for organizations deploying these devices.

  • CVE-2026-10179HIGH 8.8

    A stack-based buffer overflow vulnerability affects the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. An authenticated attacker can send a specially crafted request to the wireless encryption settings function, causing a memory overflow that could lead to remote code execution. The router has been end-of-life since 2009, and the vendor has stated they cannot fix the issue due to the product's age.

  • CVE-2026-10181HIGH 8.8

    A stack-based buffer overflow vulnerability affects the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated remote attacker can exploit this by manipulating the 'submit-url' parameter in the /goform/formSysCmd endpoint, potentially leading to code execution or system crash. However, this device has been end-of-life since 2009, and the vendor has stated it will not be patching the issue due to the product's age.

  • CVE-2026-10183HIGH 8.8

    A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) in the WLAN configuration handler. An authenticated attacker can send a specially crafted request to the `/goform/formWlanSetup` endpoint with an oversized 'enrollee' parameter, causing the application to crash or potentially execute arbitrary code on the device. The vendor confirms this product reached end-of-life in 2009 and will not issue patches.

  • CVE-2026-10188HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). An authenticated remote attacker can exploit this flaw by manipulating the staMac parameter passed to the cgistaKickOff function in the HTTP daemon (/bin/httpd), potentially executing arbitrary code with elevated privileges. Public exploit code is available, elevating the practical risk of this vulnerability.

  • CVE-2026-10189HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). The flaw is in the web server's time configuration function, which fails to properly validate user input in the 'sec' parameter. An authenticated attacker can exploit this over the network to crash the device or execute arbitrary code with the privileges of the web server process. Public exploit code is available, increasing practical risk.

  • CVE-2026-10191HIGH 8.8

    A stack-based buffer overflow exists in Tenda W12 firmware version 3.0.0.7(4763) within the Wi-Fi MAC filter configuration function. An authenticated attacker can exploit this by sending a specially crafted MAC address list parameter to the web interface, causing memory corruption that may lead to code execution, information disclosure, or service disruption. The vulnerability is reachable over the network and exploit code has been made publicly available.

  • CVE-2026-10192HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). An authenticated attacker can send a specially crafted time-setting request to the web interface that causes a memory corruption condition, potentially allowing arbitrary code execution on the affected device. Public exploit code is available, increasing the practical risk.

  • CVE-2026-10206HIGH 8.8

    D-Link DI-8400 routers contain a stack-based buffer overflow vulnerability in the /dbsrv.asp file that can be exploited by authenticated attackers to gain complete control of the device. By manipulating a specific parameter, an attacker with valid credentials can overflow memory on the router and execute arbitrary code remotely. This vulnerability affects firmware versions up to 16.07.26A1, and proof-of-concept code is publicly available, raising the risk of active exploitation.

  • CVE-2026-10259HIGH 8.8

    H3C Magic B0 devices running firmware up to version 100R002 contain a remotely exploitable vulnerability in their web interface. An authenticated attacker can send a specially crafted request to the SetMobileAPInfoById function that causes a stack-based buffer overflow, potentially allowing them to execute arbitrary code on the affected device. Public exploit details are already available, elevating the practical risk.

  • CVE-2026-10270HIGH 8.8

    D-Link DI-7001 MINI routers running firmware version 19.09.19A1 and earlier contain a stack-based buffer overflow in the web API debug interface. An attacker with valid login credentials can send a specially crafted request to the /httpd_debug.asp endpoint that overflows a buffer, potentially allowing arbitrary code execution on the device. Exploit code has been publicly disclosed, elevating near-term risk.

  • CVE-2026-10292HIGH 8.8

    A stack-based buffer overflow exists in UTT HiPER 1200GW network devices running firmware version 2.5.3-170306 and earlier. The vulnerability resides in the task editing form handler and is exploitable by authenticated remote attackers. An attacker with valid credentials can send a specially crafted request that overflows a buffer, potentially allowing arbitrary code execution on the device. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-10293HIGH 8.8

    A stack-based buffer overflow vulnerability exists in UTT HiPER 1200GW networking devices (versions up to 2.5.3-170306). An attacker with valid login credentials can send a specially crafted request to the firewall configuration endpoint that causes the device to overflow its memory, potentially leading to code execution, data theft, or denial of service. Public exploit code is available, elevating the practical risk.

  • CVE-2026-11024HIGH 8.8

    A stack buffer overflow vulnerability exists in the Skia graphics library, which is used by Google Chrome. An attacker could craft a malicious HTML page that, when viewed by a user, potentially corrupts stack memory and compromises the browser process. The vulnerability requires user interaction (visiting a malicious webpage) but presents significant risk because it can lead to code execution with the privileges of the Chrome process. Google Chrome versions prior to 149.0.7827.53 are affected.

  • CVE-2026-11413HIGH 8.8

    A stack-based buffer overflow vulnerability exists in JingDong JD Cloud Box AX6600 running firmware version 4.5.3.r4546. An authenticated attacker can send a specially crafted request to the set_macfilter function in the device's web RPC service to overflow the stack and potentially execute arbitrary code. The vulnerability is remotely exploitable and exploit code has already been publicly disclosed, making it a concrete risk for organizations using this router model.

  • CVE-2026-11498HIGH 8.8

    Tenda wireless routers (models HG7, HG9, and HG10) contain a critical flaw in their web-based management interface. An authenticated attacker can send a specially crafted request to the VoIP settings page that overwrites memory on the router, leading to complete compromise of the device. The vulnerability requires a valid login but can be exploited over the network without user interaction. Once exploited, an attacker gains full control over the router's functions, including potential interception of network traffic and manipulation of connected devices.

  • CVE-2026-11503HIGH 8.8

    Tenda's CX12L router model 16.03.53.12 contains a critical flaw in its Wi-Fi configuration interface that allows authenticated attackers to crash the device or execute arbitrary code by sending specially crafted requests with oversized network names (SSIDs). The vulnerability exists in the fast_setting_wifi_set function and has been publicly disclosed, increasing the risk of active exploitation.

  • CVE-2026-11504HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda CX12L routers running firmware version 16.03.53.12. The flaw is in the Wi-Fi scheduling feature and can be exploited by authenticated users to corrupt memory and potentially execute arbitrary code. An attacker with valid login credentials can send specially crafted scheduling parameters that overflow a buffer, compromising the router's confidentiality, integrity, and availability. Public exploit code has emerged, increasing active risk.

  • CVE-2026-11522HIGH 8.8

    Tenda W20E routers running firmware version 15.11.0.6 contain a stack-based buffer overflow vulnerability in the port mirroring configuration feature. An attacker with valid network access can send a specially crafted request to the router's web interface that causes a buffer overflow when processing the portMirrorMirroredPorts parameter. This flaw allows remote code execution with full system privileges, potentially giving attackers complete control over the router and any network traffic passing through it. Public exploit code is now available, elevating the practical risk.

  • CVE-2026-11523HIGH 8.8

    A stack-based buffer overflow vulnerability has been discovered in Tenda W20E firmware version 15.11.0.6. An authenticated attacker can manipulate the 'gotoUrl' parameter in the web management interface's portal authentication function to overflow a stack buffer, potentially gaining full control of the device. Public exploits for this vulnerability are available, elevating the risk of active exploitation.

  • CVE-2026-11524HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda W20E version 15.11.0.6, specifically in the web management interface's WiFi filter rule modification function. An authenticated attacker can exploit this by sending a specially crafted request with an oversized remark parameter, allowing them to overwrite stack memory and potentially execute arbitrary code on the device. The vulnerability requires valid credentials but no user interaction, making it a practical post-authentication attack vector for network administrators or compromised accounts.

  • CVE-2026-11528HIGH 8.8

    A stack-based buffer overflow vulnerability affects Tenda AC18 running firmware version 15.03.05.05. An attacker with valid login credentials can send a specially crafted request to the web management interface's reboot status endpoint, causing a buffer overflow that could lead to arbitrary code execution on the device. The vulnerability has been publicly disclosed and exploit code is available, increasing the practical risk.

  • CVE-2026-11553HIGH 8.8

    Tenda HG7, HG9, and HG10 routers contain a dangerous flaw in their web interface that allows an authenticated attacker to crash the device or take control of it by sending a specially crafted request. The vulnerability resides in how the router processes user input for a specific configuration parameter, failing to properly validate the length of data before storing it in memory. An attacker with login credentials can exploit this remotely without any user interaction.

  • CVE-2026-11557HIGH 8.8

    A stack-based buffer overflow vulnerability has been discovered in Tenda F451 wireless router firmware versions 1.0.0.7 and 1.0.0.9. An authenticated attacker can exploit this flaw by manipulating the 'page' parameter in the Natlimit web management interface to overflow the stack memory, potentially allowing them to execute arbitrary code or crash the device. Public exploit code is available, elevating the practical risk. The vulnerability requires valid login credentials but no user interaction, making it exploitable in environments where network access and authentication are possible.

  • CVE-2026-13515HIGH 8.8

    Tenda JD12L router version 16.03.53.23 contains a stack-based buffer overflow vulnerability in its PPTP server configuration function. An authenticated attacker can exploit this flaw by sending a specially crafted request with an oversized startIp parameter, potentially causing the application to crash or allowing arbitrary code execution. The vulnerability is reachable over the network and has been publicly disclosed.

  • CVE-2026-13516HIGH 8.8

    Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the guest Wi-Fi configuration function. An authenticated attacker can exploit this by sending a specially crafted request to manipulate the 'shareSpeed' parameter, potentially allowing arbitrary code execution or device compromise. Public exploit code is available, elevating the practical risk.

  • CVE-2026-13517HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda JD12L firmware version 16.03.53.23. An authenticated remote attacker can exploit this flaw by sending a specially crafted request to the Wi-Fi configuration endpoint, potentially allowing them to execute arbitrary code or crash the device. The vulnerability affects the security_5g parameter handling in the Wi-Fi basic settings function. Public exploit code is available, increasing the practical risk of exploitation.

  • CVE-2026-13518HIGH 8.8

    Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the network address translation (NAT) settings interface. An authenticated attacker can overflow a buffer by sending a specially crafted request to the `/goform/addressNat` endpoint with a malicious `page` parameter, leading to code execution on the device. The vulnerability requires valid login credentials but poses a significant risk because exploitation is straightforward and public proof-of-concept code is available.

  • CVE-2026-13519HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Tenda JD12L routers running firmware version 16.03.53.23. An authenticated attacker can trigger the overflow by sending a specially crafted request to the NAT Static Setting function, potentially allowing them to execute arbitrary code or crash the device. Public exploit code is available, increasing the practical risk.

  • CVE-2026-13539HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1-A routers running firmware M16U1_V240425. An authenticated attacker can send a malicious POST request to the wireless configuration endpoint with an oversized Guest_ssid parameter, causing the application to write beyond allocated memory. This memory corruption can lead to unauthorized access, data theft, or complete device compromise. The vulnerability is remotely exploitable and public exploits are available, though the vendor has released a patched firmware version.

  • CVE-2026-13563HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless extender firmware version 1.04. The vulnerability is triggered when an attacker sends a specially crafted POST request to the L2TP setup endpoint, with an oversized username parameter that overwrites the call stack. An authenticated attacker can exploit this remotely to execute arbitrary code or crash the device. The vendor has not responded to early disclosure attempts, and the vulnerability details are now public.

  • CVE-2026-13564HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point model running firmware version 1.04. An authenticated remote attacker can exploit this flaw by sending a specially crafted POST request with an oversized username parameter to the PPPoE setup interface, allowing them to execute arbitrary code with full system privileges. Public exploit code is available, elevating the practical risk.

  • CVE-2026-14721HIGH 8.8

    A stack-based buffer overflow vulnerability exists in UTT HiPER 1250GW wireless gateway devices up to firmware version 3.2.7-210907-180535. An authenticated attacker can overflow a buffer in the 5GHz wireless configuration endpoint by supplying a specially crafted SSID parameter, potentially achieving remote code execution. Public exploit code is available, elevating the practical risk.

  • CVE-2026-25268HIGH 8.8

    A memory corruption vulnerability exists in multiple Qualcomm wireless chipsets and firmware when they process invalid 40 MHz channel (HT40) configurations during dynamic channel switching. An attacker with local access could exploit this flaw to corrupt memory, potentially gaining elevated privileges or crashing the system. The vulnerability affects a wide range of Qualcomm networking and wireless components used in routers, access points, fixed wireless gateways, and embedded systems.

  • CVE-2026-35083HIGH 8.8

    A stack buffer overflow vulnerability exists in MBS Solutions' industrial gateway and protocol converter products. An attacker with valid user credentials can send a specially crafted network request to trigger memory corruption, allowing them to execute arbitrary code with root-level privileges. This is a serious vulnerability because it requires no user interaction, operates over the network, and completely bypasses system security once exploited.

  • CVE-2026-35084HIGH 8.8

    A stack buffer overflow vulnerability in the dali-devconfig component affects a broad range of MBS Solutions gateway and protocol conversion devices. An attacker with basic user-level access to the network can send a specially crafted request that overwrites memory on the device, potentially achieving full root-level system compromise. This is a particularly serious issue because these devices typically operate as trusted infrastructure components in industrial and building automation networks, where an attacker gaining root access could manipulate critical system functions or pivot to downstream systems.

  • CVE-2026-35085HIGH 8.8

    A stack buffer overflow vulnerability in gdv-serverconfig affects a broad range of MBS Solutions gateway and interface devices. An authenticated attacker with standard user privileges can send a specially crafted network request to trigger the overflow and execute arbitrary code with root-level system access. The vulnerability requires valid user credentials to exploit but no user interaction, making it a significant risk in environments where user account compromise is possible.

  • CVE-2026-43623HIGH 8.8

    microtar, a lightweight TAR archive library, contains a critical flaw in how it processes TAR file headers. When an attacker crafts a malicious TAR archive with improperly formatted header fields, the library's parsing function attempts to copy data using unsafe string operations, writing far more data than the allocated buffer can hold. This corrupts memory on the stack, potentially allowing attackers to crash applications or execute arbitrary code. Any application that uses microtar to process untrusted TAR files is at risk.

  • CVE-2026-45648HIGH 8.8

    A stack-based buffer overflow vulnerability exists in Active Directory Domain Services (AD DS) that allows authenticated attackers to execute arbitrary code remotely on affected Windows Server systems. An attacker with valid domain credentials can craft a malicious request that overflows a memory buffer, potentially gaining full control of the AD DS infrastructure. The vulnerability requires network access and valid authentication, but does not require user interaction to exploit.

  • CVE-2026-48715HIGH 8.8

    A buffer overflow vulnerability exists in radvdump, a diagnostic utility included with the IPv6 router advertisement daemon (radvd). When radvdump processes specially crafted IPv6 router advertisement packets, it can write far more data than its internal buffer can hold, potentially allowing an attacker on the local network to execute arbitrary code. The main radvd daemon itself is not vulnerable. Versions of radvd prior to 2.21 are affected.

  • CVE-2026-55738HIGH 8.8

    CVE-2026-55738 is a stack buffer overflow vulnerability in rxi microtar 0.1.0, a lightweight TAR archive parsing library. The flaw exists in how the library handles TAR header fields that contain no null terminators. When a crafted TAR file is opened or parsed, an attacker can trigger out-of-bounds memory reads and writes that crash the application or potentially execute arbitrary code. The vulnerability requires user interaction (opening or parsing a malicious archive) but carries high risk due to the nature of memory corruption exploits.

  • CVE-2026-56766HIGH 8.8

    Hydra, a popular password-cracking tool, contains a critical flaw in how it handles authentication with certain server types. When a malicious server sends a specially crafted authentication challenge during login attempts to email or web services, it can trigger a memory overflow in Hydra's process. This could allow an attacker to execute arbitrary code on a system running a vulnerable version of Hydra. The vulnerability affects Hydra versions through 9.7 and has been patched in a later commit.

  • CVE-2026-7273HIGH 8.8

    A stack-based buffer overflow flaw exists in the web interface of Zyxel GS1900-48HPv2network switches. An attacker on the same local network can send a specially crafted HTTP request to the affected switch and execute arbitrary commands without needing credentials. This is a serious vulnerability because the attacker requires no authentication and the attack works reliably across local network segments.

  • CVE-2018-25383HIGH 8.4

    Free MP3 CD Ripper version 2.8 contains a critical flaw in how it processes WMA audio files. When a user opens a specially crafted malicious WMA file through the application's Convert function, the software fails to properly validate the file structure, causing a memory overflow. This overflow allows an attacker to inject and execute malicious code on the affected computer. The vulnerability is particularly serious because it can circumvent Windows DEP (Data Execution Prevention) protection—a core OS security feature—by leveraging exception handling tricks to execute arbitrary commands with the same privileges as the user running the application.

  • CVE-2026-45463HIGH 8.4

    CVE-2026-45463 is a high-severity vulnerability in Microsoft Office products that allows an attacker to execute arbitrary code on a local system without requiring any special privileges or user interaction. The flaw stems from an integer underflow bug—a condition where a numerical calculation wraps around to an unexpectedly large value, corrupting memory and enabling code execution. Because no credentials or user action are needed to trigger the vulnerability, any user with local access to an affected system is at immediate risk.

  • CVE-2026-10898HIGH 8.3

    A stack buffer overflow vulnerability exists in the GPU component of Google Chrome versions prior to 149.0.7827.53. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a malicious HTML page to break out of the browser sandbox and gain system-level code execution. While the attacker must first compromise the renderer—typically through a separate browser vulnerability or social engineering—the sandbox escape itself represents a critical escalation path that transforms a contained compromise into full system compromise.

  • CVE-2026-49759HIGH 8.2

    A stack-based buffer overflow exists in Erlang OTP's SCTP handling code that allows an unauthenticated attacker to crash the BEAM virtual machine. The vulnerability lives in how the inet_drv component processes SCTP ERROR chunks—specifically, it writes data into a fixed-size array without validating how many cause codes are being written. An attacker who can reach an open SCTP port can send a specially crafted ERROR chunk that overflows this buffer, terminating the entire Erlang VM process. While the nature of the overflow limits the attacker to causing a denial of service (they cannot reliably execute code), the impact to availability is severe. There is also a minor risk of memory disclosure, though any leaked data would already be accessible to users running the VM.

  • CVE-2026-26239HIGH 8.1

    A buffer overflow flaw in QNAP File Station 5 allows authenticated users to corrupt memory or crash the application. While the vulnerability requires an attacker to first obtain valid user credentials, the impact—potential system compromise and denial of service—warrants prompt patching. QNAP has released a fix in version 5.5.6.5208 and later.

  • CVE-2026-12218HIGH 8.0

    Yealink SIP-T46U IP phones running firmware version 108.87.50.1 contain a stack-based buffer overflow vulnerability in the web service. An attacker on the local network with user-level privileges can exploit this flaw by sending a specially crafted request to the `/api/inner/beforewifitest` endpoint, potentially executing arbitrary code or crashing the device. The vulnerability has been publicly disclosed, though the vendor is actively developing a patch.

  • CVE-2026-12220HIGH 8.0

    A stack-based buffer overflow vulnerability exists in Yealink SIP-T46U IP phones (firmware version 108.86.0.118 and potentially others) within the firmware upload mechanism. An authenticated attacker on the local network can exploit this by sending a specially crafted request to the firmware chunk upload endpoint, causing the application to write data beyond allocated buffer boundaries. This could lead to code execution or a device crash. The vulnerability requires local network access and valid credentials, which significantly constrains the attack surface but remains a serious risk in office environments where internal networks may not be fully trusted.

  • CVE-2026-12221HIGH 8.0

    Yealink SIP-T46U IP phones running firmware version 108.86.0.118 contain a stack-based buffer overflow in their firmware upgrade component. An attacker on the same local network who has valid credentials can send specially crafted upgrade requests with manipulated parameters to trigger the overflow, potentially allowing them to execute arbitrary code with the same privileges as the phone process. Proof-of-concept code has already been disclosed publicly, increasing immediate risk.

  • CVE-2026-12222HIGH 8.0

    A stack-based buffer overflow vulnerability exists in Yealink SIP-T46U IP phones running firmware version 108.86.0.118. The flaw is in the Web FastCGI Service's Bluetooth testing function, which fails to properly validate input parameters (btMac, pin, and reserved fields) when processing requests to the /api/inner/bttest endpoint. An attacker on the local network with user-level access can send specially crafted requests to overflow the stack and potentially execute arbitrary code on the phone. Public exploit code is available, increasing the practical risk.

  • CVE-2026-11979HIGH 7.8

    libxml2's xmlcatalog utility contains a stack-based buffer overflow vulnerability in its interactive shell mode. When a user provides unusually long input lines, the application fails to validate the length before copying that data into fixed-size memory buffers on the stack. This memory corruption can crash the program or, in a worst-case scenario, allow an attacker to execute arbitrary code with the privileges of the user running xmlcatalog. The issue affects the command-parsing logic within the usershell() function.

  • CVE-2026-14605HIGH 7.8

    RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the CAN (Controller Area Network) handler for Loongson LS1C devices. The flaw exists in the recvmsg function within the ls1c_can.h library component and can be exploited by a local attacker to corrupt memory on the stack, potentially leading to privilege escalation, data theft, or system compromise. An attacker must already have local system access to trigger the vulnerability, which significantly narrows the threat surface but remains serious in embedded or IoT deployment contexts where physical or administrative access may be easier to obtain.

  • CVE-2026-14606HIGH 7.8

    RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the SWM341 CAN (Controller Area Network) handler component. An attacker with local access and standard user privileges can trigger a buffer overflow through the CAN_Receive function, potentially allowing arbitrary code execution or system crash. The vulnerability is particularly concerning because exploit code has already been publicly released, making active exploitation more likely.

  • CVE-2026-34695HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. An attacker would need to trick a user into opening a malicious file—there is no remote exploitation vector. The vulnerability affects InDesign on both Windows and macOS systems.

  • CVE-2026-34697HIGH 7.8

    Adobe InDesign Desktop has a stack-based buffer overflow flaw that allows attackers to run arbitrary code on your computer if you open a malicious file. The vulnerability affects InDesign version 21.3, 20.5.3, and earlier on both Windows and macOS. It requires user interaction—the attacker must trick you into opening a crafted document—but once triggered, the code runs with your user privileges. This is a serious issue because InDesign documents are commonly shared and trusted, making social engineering attacks plausible.

  • CVE-2026-34702HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that allows attackers to execute arbitrary code with the privileges of the user running InDesign. The vulnerability requires social engineering—an attacker must trick a user into opening a specially crafted file. Once opened, the malicious file triggers the overflow and grants the attacker code execution on the victim's machine. This affects both Windows and macOS deployments of InDesign.

  • CVE-2026-34708HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires an attacker to trick a user into opening a specially crafted malicious file, making it a user-interaction-dependent threat. InCopy is Adobe's collaborative editing companion to InDesign, widely used in publishing and design workflows, so this affects organizations relying on these tools for content creation and layout work.

  • CVE-2026-43958HIGH 7.8

    CVE-2026-43958 is a stack-based buffer overflow vulnerability in rrdcached, the caching daemon component of rrdtool (a time-series data storage and graphing tool commonly used in network monitoring and systems management). An attacker with local access to the rrdcached socket can trigger the flaw by sending a specially crafted CREATE request with an oversized payload. Successful exploitation could crash the daemon, causing service disruption, or potentially enable arbitrary code execution with the privileges of the rrdcached process.

  • CVE-2026-47959HIGH 7.8

    Adobe Acrobat Reader contains a flaw in how it processes certain file content that can cause the application to crash or allow an attacker to run arbitrary code with the same permissions as the user viewing the file. The vulnerability exists in versions 24.001.30365, 26.001.21651, and earlier across Windows and macOS. An attacker would need to trick a user into opening a specially crafted PDF or related document file to exploit this issue.

  • CVE-2026-49033HIGH 7.8

    A stack-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code on an affected system. The vulnerability requires user interaction—such as opening a malicious file or clicking a link—but does not require elevated privileges to trigger. Once exploited, an attacker gains the same permissions as the user running the vulnerable application, potentially allowing full system compromise.

  • CVE-2026-50256HIGH 7.8

    The X.Org X server and Xwayland contain a buffer overflow vulnerability caused by a mismatch in how the server and its font library handle font alias names. The server reserves a 256-byte buffer for font alias processing, but the underlying libXfont2 library allows names up to 1024 bytes. An attacker can supply a specially crafted font alias name between 257 and 1023 bytes, causing the server to overflow the undersized buffer. This can crash the display server or, if the X server runs with root privileges, potentially enable privilege escalation.

  • CVE-2026-50258HIGH 7.8

    A flaw in the X.Org X server and Xwayland allows a local user to cause a crash or potentially gain elevated privileges by manipulating keyboard type configurations. The vulnerability stems from incomplete validation of keyboard shift level parameters, enabling a malicious application or user to exceed safe memory boundaries and overflow the server's stack. Because X servers often run with elevated privileges on Linux systems, this issue carries significant risk in shared or untrusted environments.

  • CVE-2026-50259HIGH 7.8

    A stack memory overflow vulnerability exists in the X.Org X server and Xwayland that allows a local attacker with limited privileges to crash the display server or potentially gain elevated privileges. The flaw stems from improper bounds checking when processing keyboard mapping configuration, where an attacker can write beyond a fixed-size array on the stack. If the X server runs with root privileges—a common configuration in many Linux environments—this becomes a path to privilege escalation.

  • CVE-2026-6687HIGH 7.6

    FatFs R0.16 and earlier have a stack overflow vulnerability in the f_getlabel() function that can be triggered when processing exFAT filesystems. The bug occurs because the code trusts the exFAT label length field (XDIR_NumLabel) without validating it against specification limits. An attacker with physical access to a device can craft a malicious exFAT filesystem that, when mounted and processed by vulnerable FatFs code, causes a stack buffer overflow. This can lead to code execution or system compromise.

  • CVE-2025-52292HIGH 7.5

    GPAC MP4Box version 2.4 contains a stack buffer overflow vulnerability in its file input handling code. An attacker can exploit this by submitting a specially crafted MP4 file, causing the application to crash or become unresponsive. This is a denial-of-service issue with no data theft or system compromise risk, but it can disrupt services that depend on MP4Box for media processing.

  • CVE-2025-60474HIGH 7.5

    A buffer overflow vulnerability in GPAC Project's MP4Box media processing tool can crash the application when given a specially crafted input file. While attackers cannot steal data or modify files through this flaw, they can disrupt services that rely on MP4Box for media processing. The vulnerability affects versions before 26.02.0 and requires no authentication or user interaction beyond supplying the malicious file.

  • CVE-2026-15167HIGH 7.5

    Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16 contain a vulnerability in how they parse DBS Etherwatch files that can cause the application to crash. An attacker can exploit this by sending a specially crafted file that triggers a stack-based buffer overflow, resulting in a denial of service. The attack requires no user privileges or interaction beyond opening a malicious file, making it a straightforward vector for disruption in environments where Wireshark is used for network analysis.

  • CVE-2026-36770HIGH 7.5

    A stack overflow vulnerability exists in Tenda US_W3V1.0BR wireless router firmware version 1.0.0.3. The flaw is in the ask_to_reboot function's handling of the Go parameter, allowing attackers to send specially crafted input that causes the router to crash or become unresponsive. This is a remote attack that requires no authentication or user interaction, making it practical to exploit at scale.

  • CVE-2026-36771HIGH 7.5

    The Tenda W3 wireless router (version 1.0.0.3 build 2204) contains a stack overflow vulnerability in how it processes the wl_radio parameter when setting wireless SSID configuration. An attacker on the network can send specially crafted input to crash the router, disrupting service for all connected devices. No authentication is required to trigger this flaw.

  • CVE-2026-36779HIGH 7.5

    A vulnerability in Tenda O3 Wireless Router firmware version 1.0.0.5(4180) allows attackers to crash the device remotely without authentication. Multiple stack overflow flaws in the fromVirtualSer function can be triggered via specially crafted HTTP requests, resulting in denial of service. An attacker on the network can send malicious traffic to render the router unavailable.

  • CVE-2026-36783HIGH 7.5

    Tenda O3 Wireless Router firmware version 1.0.0.5(4180) contains a stack overflow flaw in a function that processes domain parameters from HTTP requests. An attacker can send a specially crafted network request to crash the router, causing it to become unavailable until reboot. No authentication is required to trigger this issue.

  • CVE-2026-36784HIGH 7.5

    A stack overflow vulnerability exists in Shenzhen Tenda Technology's O3 Wireless Router (firmware version 1.0.0.5(4180)) that can be exploited through a specially crafted HTTP request targeting the ip parameter in the fromNetToolGet function. An attacker on the network can trigger this flaw to crash the router, causing a denial of service. No authentication is required, and the attack can be launched remotely.

  • CVE-2026-36785HIGH 7.5

    A stack overflow vulnerability in Tenda FH451 routers (version 1.0.0.9) allows remote attackers to crash the device without authentication. The flaw resides in how the router processes the 'page' parameter in the fromDhcpListClient function, enabling denial-of-service attacks via specially crafted HTTP requests. An attacker on the network can exploit this to disrupt router availability, potentially affecting all devices relying on that router for connectivity.

  • CVE-2026-36786HIGH 7.5

    Tenda FH451 routers running firmware version 1.0.0.9 contain a memory corruption flaw that crashes the device when attackers send specially crafted network requests. The vulnerability exploits how the device processes DHCP client list information, allowing remote attackers to knock the router offline without needing authentication. This is a straightforward denial-of-service condition with no data theft or system compromise involved.

  • CVE-2026-36789HIGH 7.5

    Tenda AC1206 routers running firmware version 15.03.06.23 contain stack overflow vulnerabilities in the DHCP configuration function that can be triggered remotely without authentication. An attacker can send a specially crafted HTTP request with malicious username or password parameters to crash the router, rendering it unavailable until it is manually restarted. This is a network-accessible denial-of-service vulnerability that requires no user interaction or login credentials.

  • CVE-2026-36791HIGH 7.5

    A stack overflow vulnerability exists in Tenda O3v3 router firmware version 1.0.0.5. Attackers can send a specially crafted HTTP request to crash the device, rendering it temporarily unavailable. The flaw is in how the device processes certain configuration parameters and does not require authentication or user interaction.

  • CVE-2026-36792HIGH 7.5

    A flaw has been discovered in Tenda W3 wireless routers (version 1.0.0.3 build 2204) that allows an attacker to crash the device remotely without authentication. By sending a specially crafted network request, an attacker can trigger a memory overflow condition that destabilizes the router's operation, rendering it unavailable until it is manually restarted. This is a denial-of-service vulnerability—the attacker cannot steal data or take control of the device, but can disrupt network connectivity for anyone relying on that router.

  • CVE-2026-36793HIGH 7.5

    A stack overflow vulnerability has been identified in Tenda W3 Wireless Router firmware version 1.0.0.3(2204). The flaw resides in how the router processes wireless network configuration requests, specifically when handling SSID (network name) parameters. An attacker can send a specially crafted network request to trigger a crash that knocks the router offline, disrupting network connectivity for all connected devices. No user interaction or authentication is required to exploit this issue.

  • CVE-2026-36794HIGH 7.5

    A Tenda W3 wireless router running firmware version 1.0.0.3(2204) contains a flaw in how it processes login credentials. An attacker can send a specially crafted web request with oversized username or password fields to crash the router, temporarily knocking it offline. No authentication is required—an attacker on the network can trigger this remotely. The vulnerability causes a denial-of-service condition but does not leak data or allow unauthorized access.

  • CVE-2026-36805HIGH 7.5

    Tenda G0 routers running firmware version 15.11.0.5 contain buffer overflow vulnerabilities in a function that handles QQ list data. An attacker can send a specially crafted HTTP request to crash the device, causing a denial of service. No authentication is required, and the attack can be launched over the network.

  • CVE-2026-36806HIGH 7.5

    Tenda W15E routers running firmware version 15.11.0.10 contain a buffer overflow vulnerability in the web authentication function. An attacker on the network can send a specially crafted HTTP request to trigger this flaw, crashing the device and disrupting service. No authentication is required to exploit this issue, and it affects the router's availability rather than confidentiality or integrity.