CWE-125
Out-of-bounds Read
Description
The product reads data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-540
CVEs mapped to this weakness (9,413)
page 145 of 471| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38333 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request. | ||
| CVE-2022-25670 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2022-25669 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2022-0400 | Hig | 0.49 | 7.5 | 0.02 | Aug 29, 2022 | An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | ||
| CVE-2021-3998 | Hig | 0.49 | 7.5 | 0.02 | Aug 24, 2022 | A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data. | ||
| CVE-2022-1069 | Hig | 0.49 | 7.5 | 0.02 | Aug 17, 2022 | A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | ||
| CVE-2022-2831 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption. | ||
| CVE-2022-20401 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2022 | In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post-authentication with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20375 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2022 | In LteRrcNrProAsnDecode of LteRrcNr_Codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-37007 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2022-31212 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2022 | An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied. | ||
| CVE-2022-20224 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2022 | In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-34743 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-34742 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-33021 | Hig | 0.49 | 7.5 | 0.01 | Jun 29, 2022 | CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30. | ||
| CVE-2021-33650 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers. | ||
| CVE-2021-33649 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers. | ||
| CVE-2021-33648 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers. | ||
| CVE-2022-20131 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2022 | In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20123 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2022 | In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… |
- risk 0.49cvss 7.5epss 0.01
Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.
- risk 0.49cvss 7.5epss 0.01
Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.49cvss 7.5epss 0.00
Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.49cvss 7.5epss 0.02
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
- risk 0.49cvss 7.5epss 0.02
A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.
- risk 0.49cvss 7.5epss 0.01
In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post-authentication with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.01
In LteRrcNrProAsnDecode of LteRrcNr_Codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.49cvss 7.5epss 0.01
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied.
- risk 0.49cvss 7.5epss 0.01
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.01
The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.49cvss 7.5epss 0.01
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…