VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 207 of 472
  • CVE-2023-45078MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45077MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45076MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45075MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-35655MedOct 11, 2023
    risk 0.44cvss 6.7epss 0.00

    In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35654MedOct 11, 2023
    risk 0.44cvss 6.7epss 0.00

    In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-39192MedOct 9, 2023
    risk 0.44cvss 6.7epss 0.00

    A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array…

  • CVE-2022-40524MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

  • CVE-2023-20774MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292228; Issue ID: ALPS07292228.

  • CVE-2023-21207MedJun 28, 2023
    risk 0.44cvss 6.7epss 0.00

    In initiateTdlsSetupInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21203MedJun 28, 2023
    risk 0.44cvss 6.7epss 0.00

    In startWpsPbcInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21153MedJun 28, 2023
    risk 0.44cvss 6.7epss 0.00

    In Do_AIMS_SET_CALL_WAITING of imsservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20724MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843841.

  • CVE-2023-20723MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843845.

  • CVE-2023-29089MedApr 14, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding…

  • CVE-2022-33297MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Linux sensors

  • CVE-2023-21064MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21063MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21062MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-33221MedFeb 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification requests.