Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2024-08-01 CVE-2024-7333 Classic Buffer Overflow vulnerability in Totolink N350Rt Firmware 9.3.5U.6139B20201216
A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216.
network
low complexity
totolink CWE-120
8.8
2024-08-01 CVE-2024-7334 Classic Buffer Overflow vulnerability in Totolink Ex1200L Firmware 9.3.5U.6146B20201023
A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023.
network
low complexity
totolink CWE-120
8.8
2024-08-01 CVE-2024-7335 Classic Buffer Overflow vulnerability in Totolink Ex200 Firmware 4.0.3C.7646B20201211
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211.
network
low complexity
totolink CWE-120
8.8
2024-08-01 CVE-2024-7331 Classic Buffer Overflow vulnerability in Totolink A3300R Firmware 17.0.0Cu.557B20221024
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical.
network
low complexity
totolink CWE-120
8.8
2024-07-30 CVE-2024-7217 Classic Buffer Overflow vulnerability in Totolink Ca300-Poe Firmware 6.2C.884
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884.
network
low complexity
totolink CWE-120
8.8
2024-07-30 CVE-2024-7213 Classic Buffer Overflow vulnerability in Totolink A7000R Firmware 9.1.0U.6268B20220504
A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504.
network
low complexity
totolink CWE-120
8.8
2024-07-30 CVE-2024-7212 Classic Buffer Overflow vulnerability in Totolink A7000R Firmware 9.1.0U.6268B20220504
A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504.
network
low complexity
totolink CWE-120
8.8
2024-07-29 CVE-2024-41038 Classic Buffer Overflow vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The wmfw V2 format introduced variable-length strings in the algorithm block header.
local
low complexity
linux CWE-120
5.5
2024-07-29 CVE-2024-41039 Classic Buffer Overflow vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix overflow checking of wmfw header Fix the checking that firmware file buffer is large enough for the wmfw header, to prevent overrunning the buffer. The original code tested that the firmware data buffer contained enough bytes for the sums of the size of the structs wmfw_header + wmfw_adsp1_sizes + wmfw_footer But wmfw_adsp1_sizes is only used on ADSP1 firmware.
local
low complexity
linux CWE-120
7.8
2024-07-29 CVE-2024-7187 Classic Buffer Overflow vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102.
network
low complexity
totolink CWE-120
8.8