VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 92 of 182
  • CVE-2024-30607HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

  • CVE-2024-30606HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

  • CVE-2024-30592HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.

  • CVE-2024-30583HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.

  • CVE-2023-51147HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

  • CVE-2023-51146HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

  • CVE-2023-51148HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

  • CVE-2024-25756HigFeb 22, 2024
    risk 0.52cvss 8.0epss 0.01

    A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.

  • CVE-2023-24334HigFeb 21, 2024
    risk 0.52cvss 8.0epss 0.00

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

  • CVE-2023-6749HigFeb 18, 2024
    risk 0.52cvss 8.0epss 0.00

    Unchecked length coming from user input in settings shell

  • CVE-2023-35634HigDec 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Windows Bluetooth Driver Remote Code Execution Vulnerability

  • CVE-2022-24973HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2022-0650HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2023-0656HigMar 2, 2023
    risk 0.52cvss 7.5epss 0.41

    A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

  • CVE-2023-23780HigFeb 16, 2023
    risk 0.52cvss 8.0epss 0.01

    A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests.

  • CVE-2022-27791HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.18

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbitrary code execution in the context of…

  • CVE-2021-44158HigJan 3, 2022
    risk 0.52cvss 8.0epss 0.01

    ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.

  • CVE-2021-22673HigMay 7, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and…

  • CVE-2020-16243HigFeb 23, 2021
    risk 0.52cvss 7.8epss 0.12

    Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. Opening a specially crafted project file could allow an attacker to exploit and execute code under the privileges of the application.

  • CVE-2020-16199HigAug 4, 2020
    risk 0.52cvss 7.8epss 0.11

    Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code,…