VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 139 of 471
  • CVE-2024-25201HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.

  • CVE-2023-43533HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

  • CVE-2023-6387HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

  • CVE-2023-44112HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2024-20687HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft AllJoyn API Denial of Service Vulnerability

  • CVE-2023-49552HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.

  • CVE-2023-43512HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.

  • CVE-2023-33116HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

  • CVE-2023-52152HigDec 28, 2023
    risk 0.49cvss 7.5epss 0.01

    mupnp/net/uri.c in mUPnP for C through 3.0.2 has an out-of-bounds read and application crash because it lacks a certain host length recalculation.

  • CVE-2023-51713HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.04

    make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.

  • CVE-2023-48410HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-48404HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-48398HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed…

  • CVE-2023-33098HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing WPA IES, when it is passed with length more than expected size.

  • CVE-2023-33097HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while processing a FTMR frame.

  • CVE-2023-33081HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.

  • CVE-2023-33080HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.

  • CVE-2023-47264HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint…

  • CVE-2023-46767HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-46766HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.