CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,567 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 33 of 72
- CVE-2024-30624HIGHCVSS 8.8EG 8.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.
- CVE-2024-30625HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.
- CVE-2024-30626HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.
- CVE-2024-30627HIGHCVSS 8.8EG 8.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function.
- CVE-2024-30628CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.
- CVE-2024-30629MEDIUMCVSS 5.7EG 5.72024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.
- CVE-2024-30630CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.
- CVE-2024-30631MEDIUMCVSS 4.3EG 4.32024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.
- CVE-2024-30632MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.
- CVE-2024-30633MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.
- CVE-2024-30634HIGHCVSS 8.0EG 8.02024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.
- CVE-2024-30636MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.
- CVE-2024-30638MEDIUMCVSS 4.3EG 4.32024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.
- CVE-2024-30639MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.
- CVE-2024-3079HIGHCVSS 7.2EG 7.22024-06-14
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
- CVE-2024-30840MEDIUMCVSS 6.5EG 6.52024-04-15
A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.
- CVE-2024-3100MEDIUMCVSS 6.7EG 6.72024-09-13
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2024-31002CRITICALCVSS 9.8EG 9.82024-04-02
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
- CVE-2024-31079MEDIUMCVSS 4.8EG 4.82024-05-29
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically time…
- CVE-2024-31163HIGHCVSS 7.2EG 7.22024-06-14
ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
- CVE-2024-31203MEDIUMCVSS 3.3EG 4.02024-07-31
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
- CVE-2024-31449HIGHCVSS 7.0EG 7.02024-10-07
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The…
- CVE-2024-31466CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port …
- CVE-2024-31467CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port …
- CVE-2024-31468CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management …
- CVE-2024-31469CRITICALCVSS 9.8EG 9.82024-05-14
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management …
- CVE-2024-31470CRITICALCVSS 9.8EG 9.82024-05-14
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Acce…
- CVE-2024-31496MEDIUMCVSS 6.7EG 6.72024-11-12
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows…
- CVE-2024-31504HIGHCVSS 7.5EG 7.52024-07-08
Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.
- CVE-2024-31570CRITICALCVSS 9.8EG 9.82024-09-19
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
- CVE-2024-31803MEDIUMCVSS 6.2EG 6.22024-05-14
Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.
- CVE-2024-32228MEDIUMCVSS 6.6EG 6.62024-07-01
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
- CVE-2024-32285HIGHCVSS 8.0EG 8.02024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
- CVE-2024-32286CRITICALCVSS 9.8EG 9.82024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
- CVE-2024-32287MEDIUMCVSS 6.5EG 6.52024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.
- CVE-2024-32288MEDIUMCVSS 6.3EG 6.32024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.
- CVE-2024-32290MEDIUMCVSS 6.7EG 6.72024-04-17
Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.
- CVE-2024-32291HIGHCVSS 7.5EG 7.52024-04-17
Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.
- CVE-2024-32293HIGHCVSS 8.0EG 8.02024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.
- CVE-2024-32299HIGHCVSS 8.8EG 8.82024-04-17
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32301CRITICALCVSS 9.8EG 9.82024-04-17
Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32302MEDIUMCVSS 6.3EG 6.32024-04-17
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32303HIGHCVSS 8.0EG 8.02024-04-17
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32305HIGHCVSS 8.8EG 8.82024-04-17
Tenda A18 v15.03.05.05 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32306MEDIUMCVSS 5.7EG 5.72024-04-17
Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32307HIGHCVSS 7.4EG 7.42024-04-17
Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-32310HIGHCVSS 8.0EG 8.02024-04-17
Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.
- CVE-2024-32311MEDIUMCVSS 6.5EG 6.52024-04-17
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
- CVE-2024-32312MEDIUMCVSS 5.7EG 5.72024-04-17
Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the adslPwd parameter of the formWanParameterSetting function.
- CVE-2024-32313MEDIUMCVSS 6.5EG 6.52024-04-17
Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →