VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 140 of 471
  • CVE-2023-46762HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-33061HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.

  • CVE-2023-33048HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing t2lm buffers.

  • CVE-2023-33047HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing no-inherit IES.

  • CVE-2023-21353HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.00

    In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21347HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-31122HigOct 23, 2023
    risk 0.49cvss 7.5epss 0.03

    Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

  • CVE-2023-35663HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.00

    In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35656HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-23581HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service.

  • CVE-2023-35661HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35652HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2023-44114HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44103HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-33027HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing rsn ies.

  • CVE-2023-33016HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN firmware while parsing MLO (multi-link operation).

  • CVE-2023-33015HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

  • CVE-2023-39908HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

  • CVE-2023-39396HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-28555HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Audio while remapping channel buffer in media codec decoding.