VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 135 of 471
  • CVE-2024-36251HigNov 26, 2024
    risk 0.49cvss 7.5epss 0.04

    The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names,…

  • CVE-2024-52726HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

  • CVE-2024-52802HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum header length check for `dhcpv6_opt_t` after processing `dhcpv6_msg_t`. This…

  • CVE-2018-9484HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.00

    In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9456HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9419HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-39179HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive…

  • CVE-2024-52876HigNov 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.

  • CVE-2024-38649HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-37400HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.02

    An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.

  • CVE-2024-50331HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

  • CVE-2024-38405HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the CU information from RNR IE.

  • CVE-2024-38403HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing BTM ML IE when per STA profile is not included.

  • CVE-2024-10387HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.08

    CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.

  • CVE-2024-47021HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43424HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

  • CVE-2024-42420HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

  • CVE-2024-39516HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial…

  • CVE-2024-43565HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-43562HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability