Vulnerabilities > Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DATE CVE VULNERABILITY TITLE RISK
2023-04-24 CVE-2023-22915 Classic Buffer Overflow vulnerability in Zyxel products
A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote unauthenticated attacker to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device.
network
low complexity
zyxel CWE-120
7.5
2023-04-24 CVE-2023-22917 Classic Buffer Overflow vulnerability in Zyxel products
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.
network
low complexity
zyxel CWE-120
7.5
2023-04-19 CVE-2021-33971 Classic Buffer Overflow vulnerability in 360 Total Security 10.8.0.1060
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow.
local
low complexity
360 CWE-120
7.8
2023-04-19 CVE-2021-33974 Classic Buffer Overflow vulnerability in 360 Total Security 10.8.0.1060/10.8.0.1213
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buffer Overflow.
network
low complexity
360 CWE-120
8.8
2023-04-17 CVE-2023-27705 Classic Buffer Overflow vulnerability in Apng Optimizer Project Apng Optimizer 1.4
APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.
network
low complexity
apng-optimizer-project CWE-120
7.5
2023-04-13 CVE-2022-33259 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
network
low complexity
qualcomm CWE-120
critical
9.8
2023-04-13 CVE-2022-33288 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
local
low complexity
qualcomm CWE-120
8.8
2023-04-12 CVE-2022-24350 Classic Buffer Overflow vulnerability in Insyde Insydeh2O
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-120
5.5
2023-04-11 CVE-2020-24736 Classic Buffer Overflow vulnerability in Ghost Sqlite3 3.27.1
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
local
low complexity
ghost CWE-120
5.5
2023-03-30 CVE-2023-25076 Classic Buffer Overflow vulnerability in Sniproxy Project Sniproxy 0.6.02/0.6.1
A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba).
network
low complexity
sniproxy-project CWE-120
critical
9.8