2518 vulnerabilities classified as CWE-121 (栈缓冲区溢出). AI Chinese analysis included.
CWE-121 represents a critical memory safety weakness where program data exceeds the allocated bounds of a stack-allocated buffer, corrupting adjacent memory structures. Attackers typically exploit this vulnerability by injecting malicious payloads that overwrite the function’s return address or saved frame pointer, thereby hijacking control flow to execute arbitrary code with the privileges of the compromised process. This exploitation is particularly dangerous because stack buffers are local variables, making the attack surface common in low-level languages like C and C++. Developers mitigate this risk by enforcing strict input validation, utilizing safe string handling functions that prevent unbounded writes, and adopting modern programming languages with automatic memory management. Additionally, implementing compiler-level protections such as stack canaries and Address Space Layout Randomization significantly raises the barrier for successful exploitation, ensuring system integrity remains intact against buffer overflow attempts.
#define BUFSIZE 256 int main(int argc, char **argv) { char buf[BUFSIZE]; strcpy(buf, argv[1]); }void host_lookup(char *user_supplied_addr){ struct hostent *hp; in_addr_t *addr; char hostname[64]; in_addr_t inet_addr(const char *cp); /*routine that ensures user_supplied_addr is in the right format for conversion */ validate_addr_form(user_supplied_addr); addr = inet_addr(user_supplied_addr); hp = gethostbyaddr( addr, sizeof(struct in_addr), AF_INET); strcpy(hostname, hp->h_name); }| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-24049 | Sonos One Speaker 缓冲区错误漏洞 — One Speaker | 9.8 | - | 2022-02-18 |
| CVE-2022-24048 | MariaDB 输入验证错误漏洞 — MariaDB | 7.8 | - | 2022-02-18 |
| CVE-2021-46643 | Bentley Systems Bentley View 安全漏洞 — View | 7.8 | - | 2022-02-18 |
| CVE-2021-46638 | Bentley Systems MicroStation 安全漏洞 — MicroStation CONNECT | 7.8 | - | 2022-02-18 |
| CVE-2021-46585 | Bentley Systems MicroStation 安全漏洞 — MicroStation CONNECT | 7.8 | - | 2022-02-18 |
| CVE-2021-46565 | Bentley Systems MicroStation 安全漏洞 — MicroStation CONNECT | 7.8 | - | 2022-02-18 |
| CVE-2022-0629 | Stack-based Buffer Overflow in vim/vim — vim/vim | 7.8 | - | 2022-02-17 |
| CVE-2022-23804 | KiCad Eda 缓冲区错误漏洞 — KiCad | 7.8 | - | 2022-02-16 |
| CVE-2022-23803 | KiCad Eda 缓冲区错误漏洞 — KiCad | 7.8 | - | 2022-02-16 |
| CVE-2021-43299 | Pjsua Api 缓冲区错误漏洞 — pjsip | 9.8 | - | 2022-02-16 |
| CVE-2021-43300 | Pjsua Api 缓冲区错误漏洞 — pjsip | 9.8 | - | 2022-02-16 |
| CVE-2021-43301 | Pjsua Api 缓冲区错误漏洞 — pjsip | 9.8 | - | 2022-02-16 |
| CVE-2022-20699 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20700 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20701 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20702 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20703 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20704 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20705 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20706 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20707 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20708 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20709 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20710 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20711 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20712 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2022-20749 | Cisco Small Business RV Series Routers Vulnerabilities — Cisco Small Business RV Series Router Firmware | 10.0 | Critical | 2022-02-10 |
| CVE-2021-46158 | Siemens Simcenter Femap 缓冲区错误漏洞 — Simcenter Femap V2020.2 | 7.8 | - | 2022-02-09 |
| CVE-2021-46155 | Siemens Simcenter Femap 缓冲区错误漏洞 — Simcenter Femap V2020.2 | 7.8 | - | 2022-02-09 |
| CVE-2021-46154 | Siemens Simcenter Femap 缓冲区错误漏洞 — Simcenter Femap V2020.2 | 7.8 | - | 2022-02-09 |
Vulnerabilities classified as CWE-121 (栈缓冲区溢出) represent 2518 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.