Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2017-05-12 CVE-2017-0594 Classic Buffer Overflow vulnerability in Google Android
An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-120
7.8
2017-05-12 CVE-2017-0465 Classic Buffer Overflow vulnerability in multiple products
An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
linux google CWE-120
7.0
2017-04-05 CVE-2017-0327 Classic Buffer Overflow vulnerability in Linux Kernel 3.10
An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
linux CWE-120
7.0
2017-03-27 CVE-2017-7269 Classic Buffer Overflow vulnerability in Microsoft Internet Information Server 6.0
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
network
low complexity
microsoft CWE-120
critical
9.8
2017-03-20 CVE-2017-6058 Classic Buffer Overflow vulnerability in Qemu
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
network
low complexity
qemu CWE-120
7.5
2017-03-10 CVE-2016-8714 Classic Buffer Overflow vulnerability in multiple products
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0.
network
low complexity
r-project debian CWE-120
8.8
2017-03-08 CVE-2017-0520 Classic Buffer Overflow vulnerability in Linux Kernel 3.10/3.18
An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
linux CWE-120
7.0
2017-03-08 CVE-2017-0481 Classic Buffer Overflow vulnerability in Google Android
An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-120
7.8
2017-03-08 CVE-2017-0306 Classic Buffer Overflow vulnerability in Linux Kernel 3.10
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
low complexity
linux CWE-120
7.8
2017-03-03 CVE-2016-10066 Classic Buffer Overflow vulnerability in Imagemagick
Buffer overflow in the ReadVIFFImage function in coders/viff.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a crafted file.
local
low complexity
imagemagick CWE-120
5.5