VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 20 of 191
  • CVE-2024-44553CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

  • CVE-2024-44551CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

  • CVE-2024-44550CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

  • CVE-2024-44549CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

  • CVE-2024-34087CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.

  • CVE-2024-44558CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

  • CVE-2024-44556CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

  • CVE-2024-44565CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

  • CVE-2024-44563CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

  • CVE-2024-41460CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.

  • CVE-2024-41459CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.

  • CVE-2024-40535CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.

  • CVE-2024-33182CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

  • CVE-2024-40416CriJul 15, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

  • CVE-2024-40414CriJul 15, 2024
    risk 0.64cvss 9.8epss 0.00

    A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

  • CVE-2024-6744CriJul 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.

  • CVE-2024-36435CriJul 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code…

  • CVE-2024-37635CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

  • CVE-2024-37634CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

  • CVE-2024-37632CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .