Vulnerabilities > Incorrect Calculation of Buffer Size

DATE CVE VULNERABILITY TITLE RISK
2020-10-15 CVE-2020-6106 Incorrect Calculation of Buffer Size vulnerability in F2Fs-Tools Project F2Fs-Tools 1.12.0/1.13.0
An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13.
local
low complexity
f2fs-tools-project CWE-131
5.5
2020-09-17 CVE-2020-6116 Incorrect Calculation of Buffer Size vulnerability in Gonitro Nitro PRO 13.13.2.242/13.16.2.300
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.
local
low complexity
gonitro CWE-131
7.8
2020-09-17 CVE-2020-6113 Incorrect Calculation of Buffer Size vulnerability in Gonitro Nitro PRO 13.13.2.242/13.16.2.300
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table.
local
low complexity
gonitro CWE-131
7.8
2020-09-15 CVE-2020-14385 Incorrect Calculation of Buffer Size vulnerability in multiple products
A flaw was found in the Linux kernel before 5.9-rc4.
local
low complexity
linux debian canonical CWE-131
5.5
2020-09-08 CVE-2020-3640 Incorrect Calculation of Buffer Size vulnerability in Qualcomm products
u'Resizing the usage table header before passing all the checks leads to the function exiting with a usage table in invalid state when a HLOS adversary calls the function with wrong input' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, QCS404, QCS610, Rennell, Saipan, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
local
low complexity
qualcomm CWE-131
7.8
2020-08-10 CVE-2020-6070 Incorrect Calculation of Buffer Size vulnerability in multiple products
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0.
7.8
2020-07-07 CVE-2020-15350 Incorrect Calculation of Buffer Size vulnerability in Riot-Os Riot 2020.04
RIOT 2020.04 has a buffer overflow in the base64 decoder.
network
low complexity
riot-os CWE-131
critical
9.8
2020-06-17 CVE-2020-11901 Incorrect Calculation of Buffer Size vulnerability in Treck Tcp/Ip
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
network
high complexity
treck CWE-131
critical
9.0
2020-06-02 CVE-2019-14078 Incorrect Calculation of Buffer Size vulnerability in Qualcomm products
Out of bound memory access while processing qpay due to not validating length of the response buffer provided by User.
local
low complexity
qualcomm CWE-131
7.8
2020-03-10 CVE-2019-19282 Incorrect Calculation of Buffer Size vulnerability in Siemens products
A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd4), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC (TIA Portal) V15.1 (All versions < V15.1 Update 5), SIMATIC WinCC (TIA Portal) V16 (All versions < V16 Update 1), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 1).
network
low complexity
siemens CWE-131
7.5