VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 210 of 472
  • CVE-2016-2180HigAug 1, 2016
    risk 0.44cvss 7.5epss 0.28

    The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp…

  • CVE-2014-7825HigNov 10, 2014
    risk 0.44cvss 7.8epss 0.01

    kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protection mechanism via a…

  • CVE-2026-65349MedAug 17, 2026
    risk 0.43cvss 6.6epss 0.00

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to cause unexpected system termination or read kernel memory.

  • CVE-2026-73583MedAug 13, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause…

  • CVE-2026-57077HigJul 16, 2026
    risk 0.43cvss 7.7epss 0.00

    YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check.…

  • CVE-2026-28521HigMar 16, 2026
    risk 0.43cvss 7.7epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result…

  • CVE-2026-27711MedFeb 26, 2026
    risk 0.43cvss 6.6epss 0.00

    NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive…

  • CVE-2026-27709MedFeb 26, 2026
    risk 0.43cvss 6.6epss 0.00

    NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can provide a malformed…

  • CVE-2026-26282MedFeb 19, 2026
    risk 0.43cvss 6.6epss 0.00

    NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap…

  • CVE-2025-58314MedNov 28, 2025
    risk 0.43cvss 6.6epss 0.00

    Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-47183MedAug 7, 2025
    risk 0.43cvss 6.6epss 0.00

    In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.

  • CVE-2025-54644MedAug 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54643MedAug 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-24988MedMar 11, 2025
    risk 0.43cvss 6.6epss 0.01

    Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

  • CVE-2025-24987MedMar 11, 2025
    risk 0.43cvss 6.6epss 0.01

    Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

  • CVE-2024-56187MedMar 10, 2025
    risk 0.43cvss 6.6epss 0.00

    In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-21341MedJan 14, 2025
    risk 0.43cvss 6.6epss 0.01

    Windows Digital Media Elevation of Privilege Vulnerability

  • CVE-2025-21327MedJan 14, 2025
    risk 0.43cvss 6.6epss 0.01

    Windows Digital Media Elevation of Privilege Vulnerability

  • CVE-2025-21324MedJan 14, 2025
    risk 0.43cvss 6.6epss 0.01

    Windows Digital Media Elevation of Privilege Vulnerability

  • CVE-2025-21310MedJan 14, 2025
    risk 0.43cvss 6.6epss 0.01

    Windows Digital Media Elevation of Privilege Vulnerability