A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.
Volume of CVEs assigned to CWE-562 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21798HIGH An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to g | Sep 15, 2021 | 7.8 | 32 | NO | NO |
CVE-2022-41837CRITICAL An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-3591MEDIUM A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause | Mar 25, 2026 | 5.4 | 24 | NO | NO |
CVE-2024-33045HIGH Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | Sep 2, 2024 | 7.8 | 23 | NO | NO |
CVE-2026-26399MEDIUM A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and pa | Apr 20, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-34553MEDIUM iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccC | Mar 31, 2026 | 4.0 | 18 | NO | NO |
CVE-2024-4418MEDIUM A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocat | May 8, 2024 | 6.2 | 17 | NO | NO |
CVE-2020-21686MEDIUM A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm fil | Aug 22, 2023 | 5.5 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.