Skip to main content

CWE archive

CWE-562 CVEs

Programmatic archive

8 CVEs tagged with CWE-5621 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-26399

Published Apr 20, 2026

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and p…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-34553

Published Mar 31, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIcc…

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3591

Published Mar 25, 2026

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2024-4418

Published May 8, 2024

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-alloca…

CVSS 6.2 · Medium

CVE-2020-21686

Published Aug 22, 2023

A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm fi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21798

Published Sep 15, 2021

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1