Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2021-29220 Classic Buffer Overflow vulnerability in HP ILO Amplifier Pack
Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12.
network
low complexity
hp CWE-120
7.2
2022-02-23 CVE-2022-22333 Classic Buffer Overflow vulnerability in IBM products
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted.
low complexity
ibm CWE-120
6.5
2022-02-14 CVE-2022-24704 Classic Buffer Overflow vulnerability in Accel-Ppp 1.10.0/1.12.0
The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.integer without any bound checks.
network
low complexity
accel-ppp CWE-120
critical
9.8
2022-02-14 CVE-2022-24705 Classic Buffer Overflow vulnerability in Accel-Ppp 1.10.0/1.12.0
The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory.
network
low complexity
accel-ppp CWE-120
critical
9.8
2022-02-11 CVE-2021-22824 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System Data Collector
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network.
network
low complexity
schneider-electric CWE-120
7.5
2022-02-11 CVE-2022-23431 Classic Buffer Overflow vulnerability in Google Android 10.0/11.0/12.0
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
local
low complexity
google CWE-120
6.7
2022-02-11 CVE-2021-30309 Classic Buffer Overflow vulnerability in Qualcomm products
Improper size validation of QXDM commands can lead to memory corruption in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-120
7.8
2022-02-11 CVE-2021-30318 Classic Buffer Overflow vulnerability in Qualcomm products
Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-120
7.8
2022-02-11 CVE-2021-30323 Classic Buffer Overflow vulnerability in Qualcomm products
Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-120
7.8
2022-02-11 CVE-2021-30324 Classic Buffer Overflow vulnerability in Qualcomm products
Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-120
6.7