VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 220 of 472
  • CVE-2026-79112MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-75370MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

  • CVE-2026-77237MedAug 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or…

  • CVE-2026-54789HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie…

  • CVE-2026-53587HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in…

  • CVE-2026-76641HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to…

  • CVE-2026-69550MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-17028MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition…

  • CVE-2026-16853MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

  • CVE-2026-70328MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-70327MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62814MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62782MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62745MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62742MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62720MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62718MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62716MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62715MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2026-62714MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.