Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-45616 Classic Buffer Overflow vulnerability in multiple products
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211).
network
low complexity
arubanetworks hp CWE-120
critical
9.8
2023-11-14 CVE-2023-28741 Classic Buffer Overflow vulnerability in Intel products
Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-120
7.8
2023-11-14 CVE-2023-29177 Classic Buffer Overflow vulnerability in Fortinet Fortiadc and Fortiddos-F
Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.
local
low complexity
fortinet CWE-120
6.7
2023-11-14 CVE-2023-43504 Classic Buffer Overflow vulnerability in Siemens Comos
A vulnerability has been identified in COMOS (All versions < V10.4.4).
network
low complexity
siemens CWE-120
critical
9.8
2023-11-13 CVE-2023-47346 Classic Buffer Overflow vulnerability in Free5Gc Free5Gc, SMF and UPF
Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.
network
low complexity
free5gc CWE-120
7.5
2023-11-13 CVE-2023-47625 Classic Buffer Overflow vulnerability in Dronecode PX4 Drone Autopilot 1.14.0
PX4 autopilot is a flight control solution for drones.
network
low complexity
dronecode CWE-120
4.3
2023-11-09 CVE-2023-47610 Classic Buffer Overflow vulnerability in Telit products
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.
network
low complexity
telit CWE-120
critical
9.8
2023-11-08 CVE-2023-43571 Classic Buffer Overflow vulnerability in Lenovo products
A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
local
low complexity
lenovo CWE-120
6.7
2023-11-08 CVE-2023-43573 Classic Buffer Overflow vulnerability in Lenovo products
A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
local
low complexity
lenovo CWE-120
6.7
2023-11-08 CVE-2023-43575 Classic Buffer Overflow vulnerability in Lenovo products
A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
local
low complexity
lenovo CWE-120
6.7