VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,817)

page 97 of 191
  • CVE-2023-27361HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is required to exploit this…

  • CVE-2024-32303HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

  • CVE-2024-32293HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.06

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.

  • CVE-2024-32285HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.

  • CVE-2024-32310HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.

  • CVE-2024-28925HigApr 9, 2024
    risk 0.52cvss 8.0epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-26180HigApr 9, 2024
    risk 0.52cvss 8.0epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-30634HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.

  • CVE-2024-30626HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.

  • CVE-2024-30625HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.

  • CVE-2024-30601HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

  • CVE-2024-30600HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

  • CVE-2024-30607HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

  • CVE-2024-30606HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

  • CVE-2024-30592HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.

  • CVE-2024-30583HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.

  • CVE-2023-51147HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

  • CVE-2023-51146HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

  • CVE-2023-51148HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

  • CVE-2024-25756HigFeb 22, 2024
    risk 0.52cvss 8.0epss 0.01

    A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.