VYPR

CWE-125

Out-of-bounds Read

BaseDraft

Description

The product reads data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-540

CVEs mapped to this weakness (9,427)

page 221 of 472
  • CVE-2026-61924MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61921MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61918MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-65819HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.00

    gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or…

  • CVE-2026-19082HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.00

    Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count…

  • CVE-2026-70368MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes,…

  • CVE-2026-67301HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB()…

  • CVE-2026-67291HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared…

  • CVE-2026-67290HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets…

  • CVE-2026-66720MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during …

  • CVE-2026-66369MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…

  • CVE-2026-66364MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…

  • CVE-2026-66349MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…

  • CVE-2026-65421MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

  • CVE-2026-63550MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …

  • CVE-2026-63033MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

  • CVE-2026-61893MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

  • CVE-2026-56758MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.

  • CVE-2026-16530MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing,…

  • CVE-2026-66337MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially…