CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 12 of 79
- CVE-2024-32301CRITICALCVSS 9.8EG 9.82024-04-17
Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-27683CRITICALCVSS 9.8EG 9.82024-04-11
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.
- CVE-2024-23086CRITICALCVSS 9.8EG 9.82024-04-08
Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the…
- CVE-2024-29756CRITICALCVSS 9.8EG 9.82024-04-05
In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-30621CRITICALCVSS 9.8EG 9.82024-04-02
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
- CVE-2024-31002CRITICALCVSS 9.8EG 9.82024-04-02
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
- CVE-2024-30630CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.
- CVE-2024-30628CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.
- CVE-2024-30622CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.
- CVE-2024-30589CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.
- CVE-2024-30587CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
- CVE-2024-30596CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.
- CVE-2024-30595CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.
- CVE-2024-28014CRITICALCVSS 9.8EG 9.82024-03-28
Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200…
- CVE-2023-45924CRITICALCVSS 9.8EG 9.82024-03-27
libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operat…
- CVE-2024-25393CRITICALCVSS 9.8EG 9.82024-03-27
A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.
- CVE-2024-28537CRITICALCVSS 9.8EG 9.82024-03-18
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
- CVE-2024-28383CRITICALCVSS 9.8EG 9.82024-03-14
Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
- CVE-2024-28535CRITICALCVSS 9.8EG 9.82024-03-12
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
- CVE-2024-25751CRITICALCVSS 9.8EG 9.82024-02-26
A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.
- CVE-2024-1783CRITICALCVSS 9.8EG 9.82024-02-23
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi of the component Web Interface. The manipulation of…
- CVE-2023-51955CRITICALCVSS 9.8EG 9.82024-01-10
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
- CVE-2023-49236CRITICALCVSS 9.8EG 9.82024-01-09
A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP …
- CVE-2023-7220CRITICALCVSS 9.8EG 9.82024-01-09
A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-bas…
- CVE-2023-7219CRITICALCVSS 9.8EG 9.82024-01-09
A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads t…
- CVE-2024-0321CRITICALCVSS 9.8EG 9.82024-01-08
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
- CVE-2023-46223CRITICALCVSS 9.8EG 9.82023-12-19
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
- CVE-2023-6888CRITICALCVSS 9.8EG 9.82023-12-17
A vulnerability classified as critical was found in PHZ76 RtspServer 1.0.0. This vulnerability affects the function ParseRequestLine of the file RtspMesaage.cpp. The manipulation leads to stack-based buffer overflow. The attack can be init…
- CVE-2023-49424CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- CVE-2023-44305CRITICALCVSS 9.8EG 9.82023-12-04
Dell DM5500 5.14.0.0, contains a Stack-based Buffer Overflow Vulnerability in the appliance. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by send…
- CVE-2023-49287CRITICALCVSS 9.8EG 9.82023-12-04
TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.
- CVE-2023-45481CRITICALCVSS 9.8EG 9.82023-11-29
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.
- CVE-2023-5055CRITICALCVSS 9.8EG 9.82023-11-21
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
- CVE-2023-4249CRITICALCVSS 9.8EG 9.82023-11-08
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of…
- CVE-2023-45225CRITICALCVSS 9.8EG 9.82023-11-08
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elemen…
- CVE-2023-43755CRITICALCVSS 9.8EG 9.82023-11-08
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsin…
- CVE-2023-3959CRITICALCVSS 9.8EG 9.82023-11-08
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements fro…
- CVE-2023-39281CRITICALCVSS 9.8EG 9.82023-11-01
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.
- CVE-2023-46564CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.
- CVE-2023-46563CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.
- CVE-2023-46562CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.
- CVE-2023-46560CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.
- CVE-2023-46559CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.
- CVE-2023-46553CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.
- CVE-2023-46552CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.
- CVE-2023-43492CRITICALCVSS 9.8EG 9.82023-10-19
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
- CVE-2023-38584CRITICALCVSS 9.8EG 9.82023-10-19
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
- CVE-2023-4601CRITICALCVSS 9.8EG 9.82023-10-18
A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted re…
- CVE-2023-45984CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
- CVE-2023-36950CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →