CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,413)
page 141 of 471| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4048 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2023 | An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. | ||
| CVE-2023-34359 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2023 | ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition. | ||
| CVE-2023-34358 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2023 | ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS… | ||
| CVE-2023-35694 | Hig | 0.49 | 7.5 | 0.00 | Jul 13, 2023 | In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-32045 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-32044 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-36201 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2023 | An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays. | ||
| CVE-2023-21226 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21224 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21223 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21201 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21197 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21186 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21180 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2023 | In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-32011 | Hig | 0.49 | 7.5 | 0.02 | Jun 14, 2023 | Windows iSCSI Discovery Service Denial of Service Vulnerability | ||
| CVE-2023-24535 | Hig | 0.49 | 7.5 | 0.01 | Jun 8, 2023 | Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic. | ||
| CVE-2023-21661 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS while parsing WLAN beacon or probe-response frame. | ||
| CVE-2023-21660 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while parsing FT Information Elements. | ||
| CVE-2023-21659 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | ||
| CVE-2023-21658 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. |
- risk 0.49cvss 7.5epss 0.01
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
- risk 0.49cvss 7.5epss 0.01
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
- risk 0.49cvss 7.5epss 0.01
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS…
- risk 0.49cvss 7.5epss 0.00
In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.
- risk 0.49cvss 7.5epss 0.00
In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.00
In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.00
In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.00
In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.49cvss 7.5epss 0.00
In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.49cvss 7.5epss 0.00
In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.49cvss 7.5epss 0.00
In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.49cvss 7.5epss 0.02
Windows iSCSI Discovery Service Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WLAN beacon or probe-response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing FT Information Elements.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing frames with missing header fields.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.