Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2018-09-10 CVE-2018-3896 Classic Buffer Overflow vulnerability in Samsung Sth-Eth-250 Firmware 0.20.17
An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17.
network
low complexity
samsung CWE-120
8.8
2018-08-28 CVE-2018-3895 Classic Buffer Overflow vulnerability in Samsung Sth-Eth-250 Firmware 0.20.17
An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17.
network
low complexity
samsung CWE-120
8.8
2018-08-23 CVE-2017-16337 Classic Buffer Overflow vulnerability in Insteon HUB 2245-222 Firmware 1012
On Insteon Hub 2245-222 devices with firmware version 1012, specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data.
network
low complexity
insteon CWE-120
8.8
2018-08-15 CVE-2018-8343 Classic Buffer Overflow vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
local
low complexity
microsoft CWE-120
7.8
2018-08-15 CVE-2018-8342 Classic Buffer Overflow vulnerability in Microsoft Windows 7 and Windows Server 2008
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2008 R2.
local
low complexity
microsoft CWE-120
7.8
2018-08-02 CVE-2017-16347 Classic Buffer Overflow vulnerability in Insteon HUB Firmware 1012
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-120
critical
9.9
2018-08-02 CVE-2017-16346 Classic Buffer Overflow vulnerability in Insteon HUB Firmware 1012
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-120
critical
9.9
2018-08-02 CVE-2017-16345 Classic Buffer Overflow vulnerability in Insteon HUB Firmware 1012
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-120
critical
9.9
2018-08-02 CVE-2017-16344 Classic Buffer Overflow vulnerability in Insteon HUB Firmware 1012
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-120
critical
9.9
2018-08-02 CVE-2017-16343 Classic Buffer Overflow vulnerability in Insteon HUB Firmware 1012
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-120
critical
9.9