← Back
CWE-131

218 CVEs • Abstraction: Base • Likelihood of Exploit: High

Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

JSON object

Loading...

CVEs (218)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Linux
2Android
Linux Kernel
May 13, 2026
May 12, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High bec...Show more
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35401052. References: QC-CR#1081711.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
May 13, 2026
Apr 12, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially craft...Show more
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."Show less
1Linux
1Linux Kernel
May 13, 2026
Apr 7, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first req...Show more
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#110666.Show less
5Debian
F5Gnu+2 more
15Arx Firmware
Debian LinuxEnterprise Linux Desktop+12 more
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN....Show more
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.Show less
4Apple
CanonicalFedoraproject+1 more
5Fedora
Mac Os XMac Os X Server+2 more
Apr 23, 2026
May 5, 2008
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbit...Show more
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.Show less
2Debian
Invisible Island
2Debian Linux
Lynx
Apr 16, 2026
Oct 17, 2005
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escap...Show more
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.Show less
1Gaim Project
1Gaim
Apr 16, 2026
Aug 16, 2005
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM s...Show more
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.Show less
1Haxx
2Curl
Libcurl
Apr 16, 2026
May 2, 2005
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengt...Show more
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.Show less
6Apache
HpOpenpkg+3 more
6Hp Ux
Http ServerOpenpkg+3 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a lengt...Show more
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.Show less
1Apache
1Http Server
Apr 16, 2026
Oct 20, 2004
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
1Oracle
7Application Server
Collaboration SuiteDatabase Server+4 more
Apr 16, 2026
Aug 4, 2004
N/A· v4
9.8 CRITICAL· v3
7.2 HIGH· v2
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
2Debian
Heimdal Project
2Debian Linux
Heimdal
Apr 16, 2026
Jul 7, 2004
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.
1Acme
1Thttpd
Apr 16, 2026
Nov 3, 2003
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expa...Show more
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.Show less
2Apple
Cyrusimap
3Cyrus Sasl
Mac Os XMac Os X Server
Apr 16, 2026
Dec 18, 2002
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) charact...Show more
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.Show less
2Debian
Sudo Project
2Debian Linux
Sudo
Apr 16, 2026
May 16, 2002
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly...Show more
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.Show less
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
3Hp
OracleSgi
3Hp Ux
IrixSolaris
Apr 16, 2026
Jun 18, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
2Hp
Sgi
2Hp Ux
Irix
Apr 16, 2026
Jun 18, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.