VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,410)

page 106 of 471
  • CVE-2022-30651HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute…

  • CVE-2022-27531HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

  • CVE-2022-30549HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-30546HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-29506HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-29488HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.01

    The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.

  • CVE-2022-26770HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-26718HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An application may be able to gain elevated privileges.

  • CVE-2022-28241HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28239HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28231HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by an out-of-bounds read vulnerability when processing a doc object, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28274HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to…

  • CVE-2022-1402HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

  • CVE-2022-1304HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

  • CVE-2022-24383HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    The affected product is vulnerable to an out-of-bounds read, which may result in code execution

  • CVE-2022-25794HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScript Byte Code 'ABC' files or information disclosure. ABC files are created by the Flash compiler and contain executable code. This…

  • CVE-2021-26623HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

  • CVE-2021-35106HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2022-27942HigMar 26, 2022
    risk 0.51cvss 7.8epss 0.01

    tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

  • CVE-2022-27941HigMar 26, 2022
    risk 0.51cvss 7.8epss 0.01

    tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.