Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2019-12-10 CVE-2019-6192 Classic Buffer Overflow vulnerability in Lenovo Power Management Driver
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.
local
low complexity
lenovo CWE-120
4.4
2019-12-04 CVE-2019-11935 Classic Buffer Overflow vulnerability in Facebook Hhvm
Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory.
network
low complexity
facebook CWE-120
critical
9.8
2019-12-03 CVE-2019-9689 Classic Buffer Overflow vulnerability in Axtls Project Axtls
process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certificate handshake message with zero certificates.
network
low complexity
axtls-project CWE-120
7.5
2019-12-03 CVE-2019-19383 Classic Buffer Overflow vulnerability in Freeftpd 1.0.8
freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).
network
low complexity
freeftpd CWE-120
8.8
2019-12-03 CVE-2019-10013 Classic Buffer Overflow vulnerability in Axtls Project Axtls
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.
network
low complexity
axtls-project CWE-120
7.5
2019-12-03 CVE-2019-7366 Classic Buffer Overflow vulnerability in Autodesk FBX Software Development KIT 2019.5
Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5.
local
low complexity
autodesk CWE-120
7.8
2019-12-02 CVE-2019-12518 Classic Buffer Overflow vulnerability in Anviz Crosschex 4.3.12/4.3.8.0
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
network
low complexity
anviz CWE-120
critical
9.8
2019-12-02 CVE-2019-19489 Classic Buffer Overflow vulnerability in Smplayer 19.5.0
SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.
local
low complexity
smplayer CWE-120
5.5
2019-11-29 CVE-2019-5247 Classic Buffer Overflow vulnerability in Huawei Atlas 300 Firmware and Atlas 500 Firmware
Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability.
local
low complexity
huawei CWE-120
5.5
2019-11-29 CVE-2019-5225 Classic Buffer Overflow vulnerability in Huawei P30 Firmware
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel.
local
low complexity
huawei CWE-120
7.8