VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,805)

page 21 of 191
  • CVE-2024-24963CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to…

  • CVE-2024-24962CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to…

  • CVE-2024-35387CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

  • CVE-2024-35580CriMay 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

  • CVE-2024-31470CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port…

  • CVE-2024-31469CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31468CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31467CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-31466CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-34943CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

  • CVE-2024-34213CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.

  • CVE-2024-34209CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

  • CVE-2024-29164CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2023-42116CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.03

    Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2024-33835CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.

  • CVE-2023-50434CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The impact could vary…

  • CVE-2024-33215CriApr 23, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

  • CVE-2024-32318CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.

  • CVE-2024-27683CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

  • CVE-2024-29756CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.00

    In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.