Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2020-8608 Classic Buffer Overflow vulnerability in multiple products
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
network
high complexity
libslirp-project debian opensuse CWE-120
5.6
2020-02-06 CVE-2014-8271 Classic Buffer Overflow vulnerability in Tianocore Edk2
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
low complexity
tianocore CWE-120
6.8
2020-02-06 CVE-2014-1958 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
network
low complexity
imagemagick canonical opensuse CWE-120
8.8
2020-02-03 CVE-2020-8597 Classic Buffer Overflow vulnerability in multiple products
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
network
low complexity
point-to-point-protocol-project wago debian canonical CWE-120
critical
9.8
2020-01-31 CVE-2013-3489 Classic Buffer Overflow vulnerability in Mpc-Hc
Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary code via a crafted RealMedia .rm file
local
low complexity
mpc-hc CWE-120
7.8
2020-01-31 CVE-2013-3488 Classic Buffer Overflow vulnerability in Mpc-Hc
Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to execute arbitrary code via a crafted MPEG-2 Transport Stream (M2TS) file.
local
low complexity
mpc-hc CWE-120
7.8
2020-01-28 CVE-2020-5211 Classic Buffer Overflow vulnerability in Nethack
In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation.
network
low complexity
nethack CWE-120
critical
9.8
2020-01-28 CVE-2020-4207 Classic Buffer Overflow vulnerability in IBM products
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers.
network
low complexity
ibm CWE-120
critical
9.8
2020-01-28 CVE-2015-8011 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
network
low complexity
lldpd-project debian fedoraproject CWE-120
critical
9.8
2020-01-28 CVE-2020-5214 Classic Buffer Overflow vulnerability in Nethack
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation.
network
low complexity
nethack CWE-120
critical
9.8