VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 131 of 191
  • CVE-2024-41466HigJul 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

  • CVE-2024-41465HigJul 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm.

  • CVE-2024-41463HigJul 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.

  • CVE-2024-41462HigJul 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

  • CVE-2024-41492HigJul 19, 2024
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-31504HigJul 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.

  • CVE-2024-29012HigJun 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

  • CVE-2024-30083HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.03

    Windows Standards-Based Storage Management Service Denial of Service Vulnerability

  • CVE-2024-26010HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.01

    A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through…

  • CVE-2024-5242HigMay 23, 2024
    risk 0.49cvss 7.5epss 0.01

    TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this…

  • CVE-2024-3286HigMay 16, 2024
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.

  • CVE-2024-1598HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.00

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.

  • CVE-2024-33782HigMay 7, 2024
    risk 0.49cvss 7.5epss 0.01

    MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

  • CVE-2023-32140HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit…

  • CVE-2024-33217HigApr 23, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.

  • CVE-2024-32317HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

  • CVE-2024-32291HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.

  • CVE-2024-30392HigApr 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC, when URL filtering is…

  • CVE-2024-30394HigApr 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS). On all Junos OS and Junos OS Evolved…

  • CVE-2024-29045HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.02

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability