VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 176 of 472
  • CVE-2025-49480HigJul 1, 2025
    risk 0.48cvss 7.4epss 0.00

    Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

  • CVE-2025-1254HigMay 8, 2025
    risk 0.48cvss 7.4epss 0.00

    Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0…

  • CVE-2025-22121HigApr 16, 2025
    risk 0.48cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff88807b003000 by task…

  • CVE-2025-32914HigApr 14, 2025
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.

  • CVE-2025-24991MedKEVMar 11, 2025
    risk 0.48cvss 5.5epss 0.02

    Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

  • CVE-2024-11614HigDec 18, 2024
    risk 0.48cvss 7.4epss 0.01

    An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a…

  • CVE-2024-27529HigNov 8, 2024
    risk 0.48cvss 8.4epss 0.00

    wasm3 139076a contains memory leaks in Read_utf8.

  • CVE-2016-20022HigJun 27, 2024
    risk 0.48cvss 8.4epss 0.00

    In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.

  • CVE-2024-36054HigMay 26, 2024
    risk 0.48cvss 7.4epss 0.00

    Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection).

  • CVE-2023-52377HigFeb 18, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2022-43650HigMar 29, 2023
    risk 0.48cvss 7.1epss 0.23

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2023-20112HigMar 23, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker…

  • CVE-2022-47630HigJan 16, 2023
    risk 0.48cvss 7.4epss 0.01

    Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about…

  • CVE-2022-22674MedKEVMay 26, 2022
    risk 0.48cvss 5.5epss 0.01

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel…

  • CVE-2021-37639HigAug 12, 2021
    risk 0.48cvss 8.4epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tensor name is not provided, TensorFlow can be tricked into dereferencing a null pointer. Alternatively, attackers can read memory outside the bounds of heap…

  • CVE-2021-21198HigApr 9, 2021
    risk 0.48cvss 7.4epss 0.02

    Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-15196HigSep 25, 2020
    risk 0.48cvss 8.5epss 0.01

    In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has the same shape as the data. The check exists for `DenseCountSparseOutput`, where both tensors are fully specified. In the sparse…

  • CVE-2020-11902HigJun 17, 2020
    risk 0.48cvss 7.3epss 0.09

    The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.

  • CVE-2019-3956HigJun 7, 2019
    risk 0.48cvss 7.4epss 0.02

    Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which could crash the application or leak sensitive information.

  • CVE-2019-3862HigMar 21, 2019
    risk 0.48cvss 7.3epss 0.08

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client…