CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,568 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 38 of 72
- CVE-2024-4252HIGHCVSS 8.8EG 8.82024-04-27
A vulnerability classified as critical has been found in Tenda i22 1.0.0.3(4687). This affects the function formSetUrlFilterRule. The manipulation of the argument groupIndex leads to stack-based buffer overflow. It is possible to initiate …
- CVE-2024-42642CRITICALCVSS 6.7EG 9.82024-09-04
Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerabili…
- CVE-2024-42815CRITICALCVSS 9.8EG 9.82024-08-19
In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target d…
- CVE-2024-4291HIGHCVSS 8.8EG 8.82024-04-27
A vulnerability was found in Tenda A301 15.13.08.12_multi_TDE01. It has been rated as critical. This issue affects the function formAddMacfilterRule of the file /goform/setBlackRule. The manipulation of the argument deviceList leads to sta…
- CVE-2024-42940HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42941HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42942HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42944HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42945HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42946HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42949HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42953HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42954HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42955HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42968HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42973HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42974HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42976HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42977HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42979HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42982HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42983HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42984HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42985HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-42986HIGHCVSS 7.5EG 7.52024-08-15
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-43031MEDIUMCVSS 4.3EG 4.32024-08-23
autMan v2.9.6 was discovered to contain an access control issue.
- CVE-2024-43032MEDIUMCVSS 4.3EG 4.32024-08-23
autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.
- CVE-2024-43048HIGHCVSS 7.8EG 7.82024-12-02
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
- CVE-2024-43050HIGHCVSS 7.8EG 7.82024-12-02
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
- CVE-2024-43549HIGHCVSS 8.8EG 8.82024-10-08
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-43630HIGHCVSS 7.8EG 7.82024-11-12
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-43661CRITICALCVSS 9.8EG 9.82025-01-09
The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the deletion of certificates. This buffer overflow can be triggered by providing a long file path to the <redacted> action …
- CVE-2024-43663CRITICALCVSS 9.8EG 9.82025-01-09
There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. Likelihood: High – Given the prevalence of these …
- CVE-2024-43689CRITICALCVSS 9.8EG 9.82024-10-21
Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitrary code may be executed.
- CVE-2024-43700HIGHCVSS 7.8EG 7.82024-08-29
xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, …
- CVE-2024-44386HIGHCVSS 7.3EG 7.32024-08-23
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
- CVE-2024-44387MEDIUMCVSS 6.5EG 6.52024-08-23
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.
- CVE-2024-44390HIGHCVSS 8.8EG 8.82024-08-23
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
- CVE-2024-44549CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
- CVE-2024-44550CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
- CVE-2024-44551CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
- CVE-2024-44553CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
- CVE-2024-44556CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
- CVE-2024-44557CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
- CVE-2024-44558CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
- CVE-2024-44563CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
- CVE-2024-44565CRITICALCVSS 9.8EG 9.82024-08-26
Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.
- CVE-2024-44589HIGHCVSS 8.8EG 8.82024-09-18
Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.
- CVE-2024-44674MEDIUMCVSS 5.7EG 5.72024-10-07
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
- CVE-2024-44859HIGHCVSS 8.0EG 8.02024-09-04
Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →