Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-10522 Classic Buffer Overflow vulnerability in Qualcomm products
While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20
network
low complexity
qualcomm CWE-120
critical
9.8
2019-11-06 CVE-2019-10496 Classic Buffer Overflow vulnerability in Qualcomm products
Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
local
low complexity
qualcomm CWE-120
7.8
2019-11-06 CVE-2019-10491 Classic Buffer Overflow vulnerability in Qualcomm products
ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
local
low complexity
qualcomm CWE-120
7.8
2019-11-06 CVE-2006-3100 Classic Buffer Overflow vulnerability in Termpkg Project Termpkg 3.3
termpkg 3.3 suffers from buffer overflow.
network
low complexity
termpkg-project CWE-120
critical
9.8
2019-10-31 CVE-2013-2075 Classic Buffer Overflow vulnerability in Call-Cc Chicken
Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
network
low complexity
call-cc CWE-120
8.8
2019-10-31 CVE-2012-6122 Classic Buffer Overflow vulnerability in Call-Cc Chicken
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
network
low complexity
call-cc CWE-120
7.5
2019-10-31 CVE-2009-5041 Classic Buffer Overflow vulnerability in Debian Overkill
overkill has buffer overflow via long player names that can corrupt data on the server machine
network
low complexity
debian CWE-120
critical
9.8
2019-10-29 CVE-2019-8287 Classic Buffer Overflow vulnerability in Tightvnc 1.3.10
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution.
network
low complexity
tightvnc CWE-120
critical
9.8
2019-10-28 CVE-2019-17181 Classic Buffer Overflow vulnerability in Intrasrv Project Intrasrv 1.0
A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03).
network
low complexity
intrasrv-project CWE-120
critical
9.8
2019-10-25 CVE-2016-2356 Classic Buffer Overflow vulnerability in Milesight IP Security Camera Firmware 20161114
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
network
low complexity
milesight CWE-120
critical
9.8