Vulnerabilities (CVE)

Filtered by CWE-120
Total 733 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25668 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.
CVE-2024-42812 1 Dlink 2 Dir-860l, Dir-860l Firmware 2025-03-17 N/A 9.8 CRITICAL
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2025-25664 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.
CVE-2025-25663 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-17 N/A 9.8 CRITICAL
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.
CVE-2024-46652 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
CVE-2024-57703 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.
CVE-2024-35571 1 Tenda 2 Ax1806, Ax1806 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
CVE-2025-25674 1 Tenda 2 Ac10, Ac10 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.
CVE-2018-6789 3 Canonical, Debian, Exim 3 Ubuntu Linux, Debian Linux, Exim 2025-03-14 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVE-2023-46012 2025-03-14 N/A 9.8 CRITICAL
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.
CVE-2024-30635 1 Tenda 2 F1202, F1202 Firmware 2025-03-13 N/A 9.8 CRITICAL
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
CVE-2024-30602 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 N/A 9.8 CRITICAL
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
CVE-2024-37632 1 Totolink 2 A3700r, A3700r Firmware 2025-03-13 N/A 9.8 CRITICAL
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
CVE-2024-30584 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 N/A 9.8 CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
CVE-2024-30593 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 N/A 9.8 CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.
CVE-2023-52370 1 Huawei 2 Emui, Harmonyos 2025-03-13 N/A 9.8 CRITICAL
Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.
CVE-2025-25343 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-05 N/A 9.8 CRITICAL
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
CVE-2021-45423 1 Pev Project 1 Pev 2025-03-03 N/A 9.8 CRITICAL
A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its components value. Therefore, the loop code assumes that exp->NumberOfFunctions is greater than ordinal at each iteration. This can lead to arbitrary code execution.
CVE-2024-51139 2025-02-28 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the "Content-Length" header of HTTP POST requests.
CVE-2023-27853 1 Netgear 2 Rax30, Rax30 Firmware 2025-02-27 N/A 9.8 CRITICAL
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.