CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,567 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 34 of 72
- CVE-2024-32315MEDIUMCVSS 4.7EG 4.72024-04-17
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
- CVE-2024-32316MEDIUMCVSS 6.5EG 6.52024-04-17
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.
- CVE-2024-32317HIGHCVSS 7.5EG 7.52024-04-17
Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
- CVE-2024-32318CRITICALCVSS 9.8EG 9.82024-04-17
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.
- CVE-2024-32320MEDIUMCVSS 5.9EG 5.92024-04-17
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.
- CVE-2024-3286HIGHCVSS 7.5EG 7.52024-05-16
A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.
- CVE-2024-33181HIGHCVSS 8.8EG 8.82024-07-16
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.
- CVE-2024-33182CRITICALCVSS 9.8EG 9.82024-07-16
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.
- CVE-2024-33211HIGHCVSS 7.3EG 7.32024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.
- CVE-2024-33212HIGHCVSS 8.8EG 8.82024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.
- CVE-2024-33213MEDIUMCVSS 6.5EG 6.52024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.
- CVE-2024-33215CRITICALCVSS 9.8EG 9.82024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
- CVE-2024-33217HIGHCVSS 7.5EG 7.52024-04-23
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.
- CVE-2024-33511CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management prot…
- CVE-2024-33512CRITICALCVSS 9.8EG 9.82024-05-01
There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point …
- CVE-2024-33513MEDIUMCVSS 5.9EG 5.92024-05-01
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the aff…
- CVE-2024-33514MEDIUMCVSS 5.3EG 5.32024-05-01
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the aff…
- CVE-2024-33515MEDIUMCVSS 5.3EG 5.32024-05-01
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the aff…
- CVE-2024-33516MEDIUMCVSS 5.3EG 5.32024-05-01
An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation…
- CVE-2024-33517MEDIUMCVSS 5.3EG 5.32024-05-01
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation o…
- CVE-2024-33518MEDIUMCVSS 5.3EG 5.32024-05-01
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation o…
- CVE-2024-33577HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could all…
- CVE-2024-33599HIGHCVSS 8.1EG 8.12024-05-06
nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow.…
- CVE-2024-33772MEDIUMCVSS 5.7EG 5.72024-05-14
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."
- CVE-2024-33781HIGHCVSS 7.5EG 7.52024-05-07
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.
- CVE-2024-33782HIGHCVSS 7.5EG 7.52024-05-07
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.
- CVE-2024-33835CRITICALCVSS 9.8EG 9.82024-05-01
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
- CVE-2024-34020MEDIUMCVSS 6.5EG 6.52024-04-29
A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.
- CVE-2024-34026CRITICALCVSS 9.0EG 9.02024-09-18
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. …
- CVE-2024-34085HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions …
- CVE-2024-34087CRITICALCVSS 9.8EG 9.82024-08-26
An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.
- CVE-2024-34171HIGHCVSS 7.8EG 7.82024-05-30
Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.
- CVE-2024-34195CRITICALCVSS 9.8EG 9.82024-08-28
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversigh…
- CVE-2024-34200HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.
- CVE-2024-34201HIGHCVSS 7.3EG 7.32024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.
- CVE-2024-34202MEDIUMCVSS 6.5EG 6.52024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.
- CVE-2024-34203LOWCVSS 3.8EG 3.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.
- CVE-2024-34207HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.
- CVE-2024-34209CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.
- CVE-2024-34212HIGHCVSS 7.3EG 7.32024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.
- CVE-2024-34213CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.
- CVE-2024-34215HIGHCVSS 7.3EG 7.32024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.
- CVE-2024-34217HIGHCVSS 7.7EG 7.72024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.
- CVE-2024-34308HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
- CVE-2024-34579HIGHCVSS 7.8EG 7.82025-01-17
Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
- CVE-2024-34773HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected applications contain a stack overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in…
- CVE-2024-34942HIGHCVSS 8.8EG 8.82024-05-14
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.
- CVE-2024-34943CRITICALCVSS 9.8EG 9.82024-05-14
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.
- CVE-2024-34944HIGHCVSS 8.8EG 8.82024-05-14
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
- CVE-2024-34946MEDIUMCVSS 6.5EG 6.52024-05-14
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →