VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 150 of 182
  • CVE-2025-52082MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.

  • CVE-2025-52081MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the usb_folder parameter.

  • CVE-2025-52080MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

  • CVE-2025-44172MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2024-49350MedMay 29, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

  • CVE-2025-44895MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

  • CVE-2025-44892MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

  • CVE-2025-45862MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.

  • CVE-2025-45847MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.

  • CVE-2025-45514MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.

  • CVE-2025-44900MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.

  • CVE-2025-28136MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

  • CVE-2025-29218MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2025-29217MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2025-29215MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.

  • CVE-2025-29118MedMar 19, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

  • CVE-2025-25634MedMar 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.

  • CVE-2025-0848MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to…

  • CVE-2024-21758MedJan 14, 2025
    risk 0.42cvss 6.4epss 0.00

    A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.

  • CVE-2024-37050MedNov 22, 2024
    risk 0.42cvss 6.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…