CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 11 of 79
- CVE-2024-46045CRITICALCVSS 9.8EG 9.82024-09-13
Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
- CVE-2024-46044CRITICALCVSS 9.8EG 9.82024-09-13
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.
- CVE-2024-45158CRITICALCVSS 9.8EG 9.82024-09-05
An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations…
- CVE-2024-34195CRITICALCVSS 9.8EG 9.82024-08-28
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversigh…
- CVE-2024-44557CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
- CVE-2024-44553CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
- CVE-2024-44551CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
- CVE-2024-44550CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
- CVE-2024-44549CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
- CVE-2024-34087CRITICALCVSS 9.8EG 9.82024-08-26
An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.
- CVE-2024-44558CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
- CVE-2024-44556CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
- CVE-2024-44565CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.
- CVE-2024-44563CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
- CVE-2024-42815CRITICALCVSS 9.8EG 9.82024-08-19
In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target d…
- CVE-2024-41461CRITICALCVSS 9.8EG 9.82024-07-24
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
- CVE-2024-41460CRITICALCVSS 9.8EG 9.82024-07-24
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.
- CVE-2024-41459CRITICALCVSS 9.8EG 9.82024-07-24
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.
- CVE-2024-40535CRITICALCVSS 9.8EG 9.82024-07-16
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.
- CVE-2024-33182CRITICALCVSS 9.8EG 9.82024-07-16
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.
- CVE-2024-40416CRITICALCVSS 9.8EG 9.82024-07-15
A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
- CVE-2024-40414CRITICALCVSS 9.8EG 9.82024-07-15
A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
- CVE-2024-6744CRITICALCVSS 9.8EG 9.82024-07-15
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system comm…
- CVE-2024-36435CRITICALCVSS 9.8EG 9.82024-07-11
An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and m…
- CVE-2024-37635CRITICALCVSS 9.8EG 9.82024-06-13
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
- CVE-2024-37634CRITICALCVSS 9.8EG 9.82024-06-13
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
- CVE-2024-37632CRITICALCVSS 9.8EG 9.82024-06-13
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
- CVE-2024-24963CRITICALCVSS 9.8EG 9.82024-05-28
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacke…
- CVE-2024-24962CRITICALCVSS 9.8EG 9.82024-05-28
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacke…
- CVE-2024-35387CRITICALCVSS 9.8EG 9.82024-05-24
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
- CVE-2024-35580CRITICALCVSS 9.8EG 9.82024-05-20
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
- CVE-2024-31470CRITICALCVSS 9.8EG 9.82024-05-14
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Acce…
- CVE-2024-31469CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management …
- CVE-2024-31468CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management …
- CVE-2024-31467CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port …
- CVE-2024-31466CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port …
- CVE-2024-34943CRITICALCVSS 9.8EG 9.82024-05-14
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.
- CVE-2024-34213CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.
- CVE-2024-34209CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.
- CVE-2024-29164CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2023-42116CRITICALCVSS 9.8EG 9.82024-05-03
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vul…
- CVE-2024-33512CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point …
- CVE-2024-33511CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management prot…
- CVE-2024-26305CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP por…
- CVE-2024-26304CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protoco…
- CVE-2024-33835CRITICALCVSS 9.8EG 9.82024-05-01
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
- CVE-2023-50434CRITICALCVSS 9.8EG 9.82024-04-29
emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdn…
- CVE-2024-33215CRITICALCVSS 9.8EG 9.82024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
- CVE-2024-32318CRITICALCVSS 9.8EG 9.82024-04-17
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.
- CVE-2024-32286CRITICALCVSS 9.8EG 9.82024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →