CWE-121— Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).— MITRE CWE catalog
3,327 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-121page 32 of 67
- CVE-2024-30293HIGHCVSS 7.8EG 7.82024-05-16
Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction …
- CVE-2024-30392HIGHCVSS 7.5EG 7.52024-04-12
A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX Series platforms with SPC3 a…
- CVE-2024-30394HIGHCVSS 7.5EG 7.52024-04-12
A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS). On a…
- CVE-2024-30583HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.
- CVE-2024-30585MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
- CVE-2024-30586MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.
- CVE-2024-30587CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
- CVE-2024-30588MEDIUMCVSS 4.3EG 4.32024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
- CVE-2024-30589CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.
- CVE-2024-30590MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
- CVE-2024-30591HIGHCVSS 8.8EG 8.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
- CVE-2024-30592HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.
- CVE-2024-30594MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
- CVE-2024-30595CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.
- CVE-2024-30596CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.
- CVE-2024-30597MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
- CVE-2024-30598MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.
- CVE-2024-30599HIGHCVSS 8.8EG 8.82024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
- CVE-2024-30600HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
- CVE-2024-30601HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
- CVE-2024-30603MEDIUMCVSS 6.5EG 6.52024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
- CVE-2024-30604HIGHCVSS 7.5EG 7.52024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.
- CVE-2024-30606HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.
- CVE-2024-30607HIGHCVSS 8.0EG 8.02024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
- CVE-2024-30612HIGHCVSS 8.1EG 8.12024-03-28
Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.
- CVE-2024-30621CRITICALCVSS 9.8EG 9.82024-04-02
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
- CVE-2024-30622CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.
- CVE-2024-30623MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.
- CVE-2024-30624HIGHCVSS 8.8EG 8.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.
- CVE-2024-30625HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.
- CVE-2024-30626HIGHCVSS 8.0EG 8.02024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.
- CVE-2024-30627HIGHCVSS 8.8EG 8.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function.
- CVE-2024-30628CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.
- CVE-2024-30629MEDIUMCVSS 5.7EG 5.72024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.
- CVE-2024-30630CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.
- CVE-2024-30631MEDIUMCVSS 4.3EG 4.32024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.
- CVE-2024-30632MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.
- CVE-2024-30633MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.
- CVE-2024-30634HIGHCVSS 8.0EG 8.02024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.
- CVE-2024-30636MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.
- CVE-2024-30638MEDIUMCVSS 4.3EG 4.32024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.
- CVE-2024-30639MEDIUMCVSS 6.5EG 6.52024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.
- CVE-2024-3079HIGHCVSS 7.2EG 7.22024-06-14
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
- CVE-2024-30840MEDIUMCVSS 6.5EG 6.52024-04-15
A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.
- CVE-2024-3100MEDIUMCVSS 6.7EG 6.72024-09-13
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2024-31002CRITICALCVSS 9.8EG 9.82024-04-02
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
- CVE-2024-31079MEDIUMCVSS 4.8EG 4.82024-05-29
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically time…
- CVE-2024-31163HIGHCVSS 7.2EG 7.22024-06-14
ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
- CVE-2024-31203LOWCVSS 3.3EG 4.02024-07-31
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
- CVE-2024-31449HIGHCVSS 7.0EG 7.02024-10-07
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The…
Map vulnerabilities like CWE-121 to your infrastructure
EchelonGraph correlates every CVE — across CWE-121 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →