VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 142 of 471
  • CVE-2023-21658HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.

  • CVE-2021-46794HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

  • CVE-2021-46765HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.

  • CVE-2021-46749HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

  • CVE-2021-31239HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.02

    An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.

  • CVE-2022-25731HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in modem due to buffer over-read while processing packets from DNS server

  • CVE-2023-24931HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Secure Channel Denial of Service Vulnerability

  • CVE-2023-27730HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.

  • CVE-2023-27728HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.

  • CVE-2023-27727HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.

  • CVE-2023-22845HigMar 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-21060HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In sms_GetTpPiIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21059HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21053HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21028HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string without a null-terminator. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-40535HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while sending a packet to device.

  • CVE-2022-33309HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.

  • CVE-2023-20948HigFeb 28, 2023
    risk 0.49cvss 7.5epss 0.00

    In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-32830HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.6, iOS 15.6 and iPadOS 15.6. Processing a maliciously crafted image may lead to disclosure of user information.

  • CVE-2023-26253HigFeb 21, 2023
    risk 0.49cvss 7.5epss 0.01

    In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.