VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 153 of 182
  • CVE-2024-27569MedMar 1, 2024
    risk 0.42cvss 6.5epss 0.01

    LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2024-27568MedMar 1, 2024
    risk 0.42cvss 6.5epss 0.01

    LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2024-27567MedMar 1, 2024
    risk 0.42cvss 6.5epss 0.01

    LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-41712MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

  • CVE-2023-41711MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.

  • CVE-2023-39280MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.

  • CVE-2023-39279MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.

  • CVE-2023-39278MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.

  • CVE-2023-39277MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.

  • CVE-2023-39276MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.

  • CVE-2023-4527MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function…

  • CVE-2023-20250MedSep 6, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of requests…

  • CVE-2023-29182MedAug 17, 2023
    risk 0.42cvss 6.4epss 0.00

    A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.

  • CVE-2023-22363MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)

  • CVE-2023-23781MedFeb 16, 2023
    risk 0.42cvss 6.4epss 0.01

    A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML files.

  • CVE-2022-3228MedOct 28, 2022
    risk 0.42cvss 6.5epss 0.00

    Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM100 Communications Module Firmware versions v5.0.155 and prior. This may allow an attacker to crash…

  • CVE-2022-40160MedOct 6, 2022
    risk 0.42cvss 6.5epss 0.01

    ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google…

  • CVE-2022-40159MedOct 6, 2022
    risk 0.42cvss 6.5epss 0.01

    ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google…

  • CVE-2022-40151MedSep 16, 2022
    risk 0.42cvss 6.5epss 0.01

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

  • CVE-2022-2402MedSep 6, 2022
    risk 0.42cvss 6.5epss 0.00

    The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.