Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2019-10-25 CVE-2016-2356 Classic Buffer Overflow vulnerability in Milesight IP Security Camera Firmware 20161114
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
network
low complexity
milesight CWE-120
critical
9.8
2019-10-22 CVE-2019-4523 Classic Buffer Overflow vulnerability in IBM DB2 High Performance Unload Load 6.1/6.5
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
local
low complexity
ibm CWE-120
7.8
2019-10-17 CVE-2019-17666 Classic Buffer Overflow vulnerability in multiple products
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
low complexity
linux debian canonical CWE-120
8.8
2019-10-14 CVE-2017-14948 Classic Buffer Overflow vulnerability in Dlink products
Certain D-Link products are affected by: Buffer Overflow.
network
low complexity
dlink CWE-120
critical
9.8
2019-10-10 CVE-2019-17320 Classic Buffer Overflow vulnerability in Netsarang Xftp
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server.
network
low complexity
netsarang CWE-120
critical
9.8
2019-10-09 CVE-2019-17415 Classic Buffer Overflow vulnerability in Upredsun File Sharing Wizard 1.5.0
A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.
network
low complexity
upredsun CWE-120
critical
9.8
2019-10-09 CVE-2019-17402 Classic Buffer Overflow vulnerability in multiple products
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
network
low complexity
exiv2 debian canonical CWE-120
6.5
2019-10-08 CVE-2019-17247 Classic Buffer Overflow vulnerability in Irfanview 4.53
IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x0000000000007da8.
local
low complexity
irfanview CWE-120
7.8
2019-10-08 CVE-2019-17244 Classic Buffer Overflow vulnerability in Irfanview 4.53
IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000001d8a.
local
low complexity
irfanview CWE-120
7.8
2019-10-08 CVE-2019-17243 Classic Buffer Overflow vulnerability in Irfanview 4.53
IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000003155.
local
low complexity
irfanview CWE-120
7.8