Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2006-03-02 CVE-2006-0963 Classic Buffer Overflow vulnerability in Stlport Project Stlport 5.0.2
Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified functions in num_put_float.cpp.
local
low complexity
stlport-project CWE-120
4.6
2004-12-06 CVE-2004-0455 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
local
low complexity
www-sql-project debian CWE-120
7.2
2004-08-06 CVE-2004-0210 Classic Buffer Overflow vulnerability in Microsoft Interix, Windows 2000 and Windows NT
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
local
low complexity
microsoft CWE-120
7.8
2003-12-31 CVE-2003-1388 Classic Buffer Overflow vulnerability in Opera Browser 7.02
Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.
network
opera CWE-120
critical
9.3
2003-12-31 CVE-2003-1387 Classic Buffer Overflow vulnerability in Opera Browser 6.05/6.06/7.0
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.
network
low complexity
opera CWE-120
7.5
2003-12-31 CVE-2003-1228 Classic Buffer Overflow vulnerability in Mathopd
Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.
network
low complexity
mathopd CWE-120
7.5
2003-12-15 CVE-2003-0947 Classic Buffer Overflow vulnerability in Wireless Tools Project Wireless Tools
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.
local
low complexity
wireless-tools-project CWE-120
7.2
2003-06-09 CVE-2003-0358 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
local
low complexity
falconseye-project nethack debian CWE-120
4.6
2002-10-11 CVE-2002-0969 Classic Buffer Overflow vulnerability in Oracle Mysql
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
local
low complexity
oracle CWE-120
7.8
2001-08-14 CVE-2001-0554 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
network
low complexity
netkit mit sgi freebsd ibm netbsd openbsd sun debian CWE-120
critical
10.0