It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and caus
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kern
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. I
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i
Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing
A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter
IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer o
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a
Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially ex
Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lea
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser
Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to tr
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local d
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local d
In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as inpu
A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processin
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authent
NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i
A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8
A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtua
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7
A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I
A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions <
Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may al
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic
A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9.
A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV3
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV3
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arb
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W
A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper va
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables
Frequently Asked Questions
What is CWE-121?
CWE-121 (CWE-121) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-121?
There are 3,705 CVE records associated with CWE-121 in our database. Of these, 678 are critical severity, 2274 are high severity, and 569 are medium severity.
How can I protect against CWE-121 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-121 using AI-powered security agents.
Detect CWE-121 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-121 vulnerabilities across your infrastructure.
Get Started