VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,413)

page 143 of 471
  • CVE-2022-35729HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access.

  • CVE-2023-21702HigFeb 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows iSCSI Service Denial of Service Vulnerability

  • CVE-2023-21691HigFeb 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability

  • CVE-2022-40512HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.

  • CVE-2022-34145HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN Host while parsing frame information.

  • CVE-2022-33306HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.

  • CVE-2023-21539HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows Authentication Remote Code Execution Vulnerability

  • CVE-2022-33286HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.

  • CVE-2022-33285HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.

  • CVE-2022-33253HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.

  • CVE-2021-46868HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

  • CVE-2021-46867HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

  • CVE-2021-38561HigDec 26, 2022
    risk 0.49cvss 7.5epss 0.01

    golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

  • CVE-2022-41988HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger…

  • CVE-2022-46317HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-42524HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20605HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In SAECOMM_CopyBufferBytes of SAECOMM_Utility.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-23483HigDec 9, 2022
    risk 0.49cvss 7.5epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to…

  • CVE-2022-33237HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2022-33236HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking