VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 196 of 472
  • CVE-2021-29964HigJun 24, 2021
    risk 0.46cvss 7.1epss 0.01

    A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11,…

  • CVE-2021-32950HigJun 17, 2021
    risk 0.46cvss 7.1epss 0.02

    An out-of-bounds read issue exists within the parsing of DXF files in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a…

  • CVE-2021-32940HigJun 17, 2021
    risk 0.46cvss 7.1epss 0.02

    An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All versions prior to 2022.5) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allow attackers to…

  • CVE-2021-32938HigJun 17, 2021
    risk 0.46cvss 7.1epss 0.01

    Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing of DWG files resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a…

  • CVE-2020-11161HigJun 9, 2021
    risk 0.46cvss 7.1epss 0.00

    Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external components in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-32614HigMay 26, 2021
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC bytes from it. The length of the buffer is controlled by an attacker. By providing a length smaller than 0xCC, memcpy reaches out of the malloc'ed bound. This…

  • CVE-2021-3548HigMay 26, 2021
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach…

  • CVE-2020-24119HigMay 14, 2021
    risk 0.46cvss 7.1epss 0.01

    A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.

  • CVE-2020-23922HigApr 21, 2021
    risk 0.46cvss 7.1epss 0.02

    An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

  • CVE-2020-23921HigApr 21, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in fast_ber through v0.4. yy::yylex() in asn_compiler.hpp has a heap-based buffer over-read.

  • CVE-2021-3506HigApr 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal…

  • CVE-2020-9930HigApr 2, 2021
    risk 0.46cvss 7.1epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. A local user may be able to cause unexpected system termination or read kernel memory.

  • CVE-2020-27936HigApr 2, 2021
    risk 0.46cvss 7.1epss 0.00

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A local user may be able to cause…

  • CVE-2021-21076HigMar 12, 2021
    risk 0.46cvss 7.1epss 0.03

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-21075HigMar 12, 2021
    risk 0.46cvss 7.1epss 0.03

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-21074HigMar 12, 2021
    risk 0.46cvss 7.1epss 0.03

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-21073HigMar 12, 2021
    risk 0.46cvss 7.1epss 0.03

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-21072HigMar 12, 2021
    risk 0.46cvss 7.1epss 0.03

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-27364HigMar 7, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

  • CVE-2020-27002HigFeb 9, 2021
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a memory access past the end of an…