Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2020-09-18 CVE-2020-25756 Classic Buffer Overflow vulnerability in Cesanta Mongoose 6.18
A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking.
network
low complexity
cesanta CWE-120
critical
9.8
2020-09-16 CVE-2020-24889 Classic Buffer Overflow vulnerability in Libraw
A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.
local
low complexity
libraw CWE-120
7.8
2020-09-15 CVE-2020-8927 Classic Buffer Overflow vulnerability in multiple products
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.
6.5
2020-09-11 CVE-2020-25279 Classic Buffer Overflow vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software.
network
low complexity
google CWE-120
7.5
2020-09-09 CVE-2020-15173 Classic Buffer Overflow vulnerability in Accel-Ppp 1.10.0/1.12.0/1.12.092G38B6104
In ACCEL-PPP (an implementation of PPTP/PPPoE/L2TP/SSTP), there is a buffer overflow when receiving an l2tp control packet ith an AVP which type is a string and no hidden flags, length set to less than 6.
network
low complexity
accel-ppp CWE-120
7.5
2020-09-09 CVE-2018-17773 Classic Buffer Overflow vulnerability in Ingenico Telium 2 Firmware
Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol.
low complexity
ingenico CWE-120
6.8
2020-09-09 CVE-2018-17770 Classic Buffer Overflow vulnerability in Ingenico Telium 2 Firmware
Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol.
local
low complexity
ingenico CWE-120
7.2
2020-09-09 CVE-2018-17769 Classic Buffer Overflow vulnerability in Ingenico Telium 2 Firmware
Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol.
low complexity
ingenico CWE-120
6.6
2020-09-09 CVE-2020-2042 Classic Buffer Overflow vulnerability in Paloaltonetworks Pan-Os 10.0.0
A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges.
network
low complexity
paloaltonetworks CWE-120
critical
9.0
2020-09-09 CVE-2020-2040 Classic Buffer Overflow vulnerability in Paloaltonetworks Pan-Os
A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface.
network
low complexity
paloaltonetworks CWE-120
critical
10.0