CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,567 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 29 of 72
- CVE-2024-20524MEDIUMCVSS 6.8EG 6.82024-10-02
A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, r…
- CVE-2024-20688HIGHCVSS 7.1EG 7.12024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-20689HIGHCVSS 7.1EG 7.12024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-20772HIGHCVSS 7.8EG 7.82024-04-10
Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2024-20998MEDIUMCVSS 4.9EG 4.92024-04-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker wit…
- CVE-2024-21030MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21053MEDIUMCVSS 4.9EG 4.92024-04-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multip…
- CVE-2024-21054MEDIUMCVSS 4.9EG 4.92024-04-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker wit…
- CVE-2024-21474HIGHCVSS 8.4EG 8.42024-05-06
Memory corruption when size of buffer from previous call is used without validation or re-initialization.
- CVE-2024-21758MEDIUMCVSS 6.4EG 6.42025-01-14
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb …
- CVE-2024-22949CRITICALCVSS 9.1EG 9.12024-04-08
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the…
- CVE-2024-23086CRITICALCVSS 9.8EG 9.82024-04-08
Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the…
- CVE-2024-23110HIGHCVSS 7.8EG 7.82024-06-11
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands…
- CVE-2024-23125HIGHCVSS 7.8EG 7.82024-02-22
A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…
- CVE-2024-23126HIGHCVSS 7.8EG 7.82024-02-22
A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitr…
- CVE-2024-23138HIGHCVSS 7.8EG 7.82024-03-18
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the…
- CVE-2024-23374MEDIUMCVSS 6.7EG 6.72024-10-07
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
- CVE-2024-23594MEDIUMCVSS 6.4EG 6.42024-04-15
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute…
- CVE-2024-23797HIGHCVSS 7.8EG 7.82024-02-13
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications contain a stack overflow vulnerability while par…
- CVE-2024-23798HIGHCVSS 7.8EG 7.82024-02-13
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications contain a stack overflow vulnerability while par…
- CVE-2024-23804HIGHCVSS 7.8EG 7.82024-02-13
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications contain a stack overflow vulnerability while par…
- CVE-2024-23933MEDIUMCVSS 6.8EG 6.82024-09-23
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentica…
- CVE-2024-23934HIGHCVSS 8.8EG 8.82024-09-23
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is…
- CVE-2024-23935HIGHCVSS 8.0EG 8.02024-09-28
Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must fir…
- CVE-2024-23938HIGHCVSS 8.8EG 8.82024-09-28
Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authe…
- CVE-2024-23957HIGHCVSS 8.8EG 8.82024-09-28
Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel Ma…
- CVE-2024-23959HIGHCVSS 8.0EG 8.02024-09-28
Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Aut…
- CVE-2024-23967HIGHCVSS 8.0EG 8.02024-09-28
Autel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of …
- CVE-2024-23982HIGHCVSS 7.5EG 7.52024-02-14
When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released be…
- CVE-2024-24684HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulne…
- CVE-2024-24685HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulne…
- CVE-2024-24686HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulne…
- CVE-2024-2485HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer …
- CVE-2024-2486HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer ov…
- CVE-2024-2487HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName/mac leads to st…
- CVE-2024-2488HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIP leads to stack-based buffe…
- CVE-2024-2489HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It …
- CVE-2024-2490HIGHCVSS 8.8EG 8.82024-03-15
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads t…
- CVE-2024-24962CRITICALCVSS 9.8EG 9.82024-05-28
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacke…
- CVE-2024-24963CRITICALCVSS 9.8EG 9.82024-05-28
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacke…
- CVE-2024-25137MEDIUMCVSS 4.3EG 4.32024-03-26
In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can le…
- CVE-2024-25176CRITICALCVSS 9.8EG 9.82025-07-07
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
- CVE-2024-25331CRITICALCVSS 9.3EG 9.32024-03-12
DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.
- CVE-2024-25391HIGHCVSS 8.4EG 8.42024-03-27
A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.
- CVE-2024-25393CRITICALCVSS 9.8EG 9.82024-03-27
A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.
- CVE-2024-2546HIGHCVSS 8.8EG 8.82024-03-17
A vulnerability has been found in Tenda AC18 15.13.07.09 and classified as critical. Affected by this vulnerability is the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflo…
- CVE-2024-2547HIGHCVSS 8.8EG 8.82024-03-17
A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function R7WebsSecurityHandler. The manipulation of the argument password leads to stack-based buffer overflow. The attack may be…
- CVE-2024-2558HIGHCVSS 8.8EG 8.82024-03-17
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overf…
- CVE-2024-25746HIGHCVSS 8.8EG 8.82024-02-22
Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.
- CVE-2024-25748HIGHCVSS 8.8EG 8.82024-02-22
A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetIpMacBind function.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →